From 79c3e0b92a5f066ae959e22072f09e0864b15a5d Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Mon, 16 Feb 2026 14:44:57 +0000 Subject: [PATCH 01/79] Update to 0.10.3 (close RHBZ#2440201) --- .gitignore | 1 + sources | 2 +- uv.spec | 11 ++++++++++- 3 files changed, 12 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 5b320aa..774ddda 100644 --- a/.gitignore +++ b/.gitignore @@ -190,3 +190,4 @@ /uv-0.10.0.tar.gz /uv-0.10.1.tar.gz /uv-0.10.2.tar.gz +/uv-0.10.3.tar.gz diff --git a/sources b/sources index ea7d8a1..f82f1fc 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.10.2.tar.gz) = 7592217ce76cd0a418a4979df045890e215c5bcff53d18e34924e0d57ec388fc8ce56b3fdc7ee473f131de5d04a4349b1dbb9d5a585493a0cd9a22dfd51e9cfc +SHA512 (uv-0.10.3.tar.gz) = a8f41a5fc74b30f8e0dd7bd24786148a35230f14237872211e56539f3892b02b59a0e06ad6400fa000b13c659b6286065294337c73749f6c51aca17f22ed5d69 diff --git a/uv.spec b/uv.spec index cb3154c..c0eefa0 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.10.2 +Version: 0.10.3 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -417,6 +417,8 @@ tomcli set Cargo.toml append workspace.exclude crates/uv-bench tomcli set Cargo.toml append workspace.exclude crates/uv-dev # Do not request static linking of anything (particularly, liblzma) +tomcli set Cargo.toml lists delitem \ + workspace.dependencies.xz2.features 'static' tomcli set crates/uv/Cargo.toml lists delitem \ features.default 'uv-distribution/static' tomcli set crates/uv-distribution/Cargo.toml del features.static @@ -485,6 +487,13 @@ tomcli set crates/uv/Cargo.toml del dependencies.tracing-durations-export # # https://bugzilla.redhat.com/show_bug.cgi?id=1234567 # tomcli set Cargo.toml str workspace.dependencies.foocrate.version 0.1.2 +# zip +# wanted: >=2.2.3, <7.2 +# currently packaged: 7.2 +# pinned upstream due to different output on Windows; OK on Linux +# https://github.com/zip-rs/zip2/issues/656 +tomcli set Cargo.toml str workspace.dependencies.zip.version '>=2.2.3' + %cargo_prep From acb13ef9a9c5dd0763a47f19a946ef1f79354fc6 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 18 Feb 2026 08:21:21 +0000 Subject: [PATCH 02/79] Update to 0.10.4 (close RHBZ#2440513) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 774ddda..1f40e40 100644 --- a/.gitignore +++ b/.gitignore @@ -191,3 +191,4 @@ /uv-0.10.1.tar.gz /uv-0.10.2.tar.gz /uv-0.10.3.tar.gz +/uv-0.10.4.tar.gz diff --git a/sources b/sources index f82f1fc..a59c73c 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.10.3.tar.gz) = a8f41a5fc74b30f8e0dd7bd24786148a35230f14237872211e56539f3892b02b59a0e06ad6400fa000b13c659b6286065294337c73749f6c51aca17f22ed5d69 +SHA512 (uv-0.10.4.tar.gz) = 0ca01e6d42ac1e773b0366b9ffa44806ec4c19a920f9c33c9d6cc12dbc60d7564b8667bce85628db1e571b7c478bec3946c48875a42f45f77da6be78f2de5f37 diff --git a/uv.spec b/uv.spec index c0eefa0..5a16465 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.10.3 +Version: 0.10.4 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From b28ba9320690196fba9c70008d85d49ff2653dea Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Tue, 24 Feb 2026 08:02:27 +0000 Subject: [PATCH 03/79] Update to 0.10.5 --- .gitignore | 1 + sources | 2 +- uv.spec | 9 +-------- 3 files changed, 3 insertions(+), 9 deletions(-) diff --git a/.gitignore b/.gitignore index 1f40e40..5725fc3 100644 --- a/.gitignore +++ b/.gitignore @@ -192,3 +192,4 @@ /uv-0.10.2.tar.gz /uv-0.10.3.tar.gz /uv-0.10.4.tar.gz +/uv-0.10.5.tar.gz diff --git a/sources b/sources index a59c73c..09c52e8 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.10.4.tar.gz) = 0ca01e6d42ac1e773b0366b9ffa44806ec4c19a920f9c33c9d6cc12dbc60d7564b8667bce85628db1e571b7c478bec3946c48875a42f45f77da6be78f2de5f37 +SHA512 (uv-0.10.5.tar.gz) = 7a01860e173f386f7feef10a33f9c49958e872a52df85627aadf7c09a54d4f8b01e429e91a83d96bcf7ac14ff9de01c2406fe7cb45b0128836328cd4a79895f9 diff --git a/uv.spec b/uv.spec index 5a16465..8e6bf69 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.10.4 +Version: 0.10.5 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -487,13 +487,6 @@ tomcli set crates/uv/Cargo.toml del dependencies.tracing-durations-export # # https://bugzilla.redhat.com/show_bug.cgi?id=1234567 # tomcli set Cargo.toml str workspace.dependencies.foocrate.version 0.1.2 -# zip -# wanted: >=2.2.3, <7.2 -# currently packaged: 7.2 -# pinned upstream due to different output on Windows; OK on Linux -# https://github.com/zip-rs/zip2/issues/656 -tomcli set Cargo.toml str workspace.dependencies.zip.version '>=2.2.3' - %cargo_prep From 5110a9471ede38af07a3100508852a90a940db75 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 25 Feb 2026 07:19:42 +0000 Subject: [PATCH 04/79] Update to 0.10.6 (close RHBZ#2442225) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 5725fc3..3c4c463 100644 --- a/.gitignore +++ b/.gitignore @@ -193,3 +193,4 @@ /uv-0.10.3.tar.gz /uv-0.10.4.tar.gz /uv-0.10.5.tar.gz +/uv-0.10.6.tar.gz diff --git a/sources b/sources index 09c52e8..4852594 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.10.5.tar.gz) = 7a01860e173f386f7feef10a33f9c49958e872a52df85627aadf7c09a54d4f8b01e429e91a83d96bcf7ac14ff9de01c2406fe7cb45b0128836328cd4a79895f9 +SHA512 (uv-0.10.6.tar.gz) = 5237b6961677d981af3320bb53958712c43f95de17af1d172015ba2ea80e02189b5ff9ea35d594211a4341bcaf8f55858a68ca5625c5d3dc7d17e5acaf39837d diff --git a/uv.spec b/uv.spec index 8e6bf69..6204246 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.10.5 +Version: 0.10.6 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From d318fa11f8d8d97136664877d23514931c9a06b4 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Fri, 27 Feb 2026 13:44:05 +0000 Subject: [PATCH 05/79] Update to 0.10.7 (close RHBZ#2443313) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 3c4c463..17b8f6c 100644 --- a/.gitignore +++ b/.gitignore @@ -194,3 +194,4 @@ /uv-0.10.4.tar.gz /uv-0.10.5.tar.gz /uv-0.10.6.tar.gz +/uv-0.10.7.tar.gz diff --git a/sources b/sources index 4852594..e095522 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.10.6.tar.gz) = 5237b6961677d981af3320bb53958712c43f95de17af1d172015ba2ea80e02189b5ff9ea35d594211a4341bcaf8f55858a68ca5625c5d3dc7d17e5acaf39837d +SHA512 (uv-0.10.7.tar.gz) = 9a3c6fa356c655afad15c5b454efac9c7db4a4b4870903232a7a75bfdd778a18b7d5a59aa88a561445e5898d0b2c76e33c87081b113283c8bbd43f15645d404f diff --git a/uv.spec b/uv.spec index 6204246..8436c36 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.10.6 +Version: 0.10.7 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From 30d15f1c735986be68711f28d5ad829489e45dcf Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 4 Mar 2026 07:02:19 +0000 Subject: [PATCH 06/79] Update to 0.10.8 (close RHBZ#2444235) --- .gitignore | 1 + sources | 2 +- uv.spec | 5 ++++- 3 files changed, 6 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 17b8f6c..3bdd950 100644 --- a/.gitignore +++ b/.gitignore @@ -195,3 +195,4 @@ /uv-0.10.5.tar.gz /uv-0.10.6.tar.gz /uv-0.10.7.tar.gz +/uv-0.10.8.tar.gz diff --git a/sources b/sources index e095522..804321a 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.10.7.tar.gz) = 9a3c6fa356c655afad15c5b454efac9c7db4a4b4870903232a7a75bfdd778a18b7d5a59aa88a561445e5898d0b2c76e33c87081b113283c8bbd43f15645d404f +SHA512 (uv-0.10.8.tar.gz) = d5eef1a7a46e25bbe534769c3b2894d573f50221b1dfb4ec78abaa73ec78fbe75f2cb785f2101155c5b7a7984138ff20efc3a51548a0209ffbf7aff8367e4960 diff --git a/uv.spec b/uv.spec index 8436c36..8c267e7 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.10.7 +Version: 0.10.8 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -449,6 +449,9 @@ tomcli set crates/uv-extract/Cargo.toml del features.static # default features. tomcli set crates/uv/Cargo.toml lists delitem features.test-defaults \ 'test-(crates-io|git(-lfs)?|pypi|python-managed|r2)' +# - -test-osv: Introduces a testing dependency on osv.dev. +tomcli set crates/uv-audit/Cargo.toml lists delitem features.default \ + 'test-(osv)' %if %{without it} # Integration tests (it crate) nearly all require specific Python interpreter From 5b914dbeb0ba0fc170987b2e5aac9bbda76eb84b Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sun, 8 Mar 2026 09:09:05 +0000 Subject: [PATCH 07/79] Update to 0.10.9 (close RHBZ#2445402) --- .gitignore | 1 + 18369.patch | 33 +++++++++++++++++++++++++++++++++ sources | 2 +- uv.spec | 6 +++++- 4 files changed, 40 insertions(+), 2 deletions(-) create mode 100644 18369.patch diff --git a/.gitignore b/.gitignore index 3bdd950..8d583dd 100644 --- a/.gitignore +++ b/.gitignore @@ -196,3 +196,4 @@ /uv-0.10.6.tar.gz /uv-0.10.7.tar.gz /uv-0.10.8.tar.gz +/uv-0.10.9.tar.gz diff --git a/18369.patch b/18369.patch new file mode 100644 index 0000000..d4c2e3f --- /dev/null +++ b/18369.patch @@ -0,0 +1,33 @@ +From eb875e65ebeba1236571f92234bcc8508cb2f92f Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Sun, 8 Mar 2026 13:06:37 +0000 +Subject: [PATCH] Conditionalize two new tests on the test-pypi feature + +Both `build_backend::tool_uv_build_backend_without_build_backend` and +`build_backend::tool_uv_build_backend_wrong_build_backend` fail in +offline environments because they try to download a build backend from +PyPI. +--- + crates/uv/tests/it/build_backend.rs | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/crates/uv/tests/it/build_backend.rs b/crates/uv/tests/it/build_backend.rs +index a01705a6765c4..454f2b1ad8594 100644 +--- a/crates/uv/tests/it/build_backend.rs ++++ b/crates/uv/tests/it/build_backend.rs +@@ -1449,6 +1449,7 @@ fn build_with_all_metadata() -> Result<()> { + /// Warn for cases where `tool.uv.build-backend` is used without the corresponding build backend + /// entry. + #[test] ++#[cfg(feature = "test-pypi")] + fn tool_uv_build_backend_without_build_backend() -> Result<()> { + let context = uv_test::test_context!("3.12"); + +@@ -1512,6 +1513,7 @@ fn tool_uv_build_backend_without_build_backend() -> Result<()> { + /// Warn for cases where `tool.uv.build-backend` is used without the corresponding build backend + /// entry. + #[test] ++#[cfg(feature = "test-pypi")] + fn tool_uv_build_backend_wrong_build_backend() -> Result<()> { + let context = uv_test::test_context!("3.12"); + diff --git a/sources b/sources index 804321a..b0a112d 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.10.8.tar.gz) = d5eef1a7a46e25bbe534769c3b2894d573f50221b1dfb4ec78abaa73ec78fbe75f2cb785f2101155c5b7a7984138ff20efc3a51548a0209ffbf7aff8367e4960 +SHA512 (uv-0.10.9.tar.gz) = 14a6f13aa6706a6888b471ae8ca161f5f413036624b276de10a92d29a07f759d5080ea496e0229b9c89e431c370689a25a107655bc24b65fa7972411036c6dfd diff --git a/uv.spec b/uv.spec index 8c267e7..d833d80 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.10.8 +Version: 0.10.9 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -154,6 +154,10 @@ Source1: uv.toml # https://github.com/astral-sh/uv/issues/4451 Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch +# Conditionalize two new tests on the test-pypi feature +# https://github.com/astral-sh/uv/pull/18369 +Patch: %{url}/pull/18369.patch + # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} From 24ce0367ede5ce3a86bb8774d45852022e3013ed Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sun, 15 Mar 2026 07:05:04 +0000 Subject: [PATCH 08/79] Update to 0.10.10 (close RHBZ#2447540) --- .gitignore | 1 + ...-always-find-the-system-wide-uv-exec.patch | 6 ++-- 18369.patch | 33 ------------------- sources | 2 +- uv.spec | 6 +--- 5 files changed, 6 insertions(+), 42 deletions(-) delete mode 100644 18369.patch diff --git a/.gitignore b/.gitignore index 8d583dd..31f7a7a 100644 --- a/.gitignore +++ b/.gitignore @@ -197,3 +197,4 @@ /uv-0.10.7.tar.gz /uv-0.10.8.tar.gz /uv-0.10.9.tar.gz +/uv-0.10.10.tar.gz diff --git a/0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch b/0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch index d60ea47..1552d94 100644 --- a/0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch +++ b/0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch @@ -1,4 +1,4 @@ -From 2a9baed6b1246c566e1bed531b17363277e99c0f Mon Sep 17 00:00:00 2001 +From 831cf2937a4b8b781d56d5fa18916d2bc42b244d Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sun, 23 Jun 2024 16:29:05 -0400 Subject: [PATCH] Downstream patch: always find the system-wide uv executable @@ -13,7 +13,7 @@ https://github.com/astral-sh/uv/issues/4451 1 file changed, 8 insertions(+) diff --git a/python/uv/_find_uv.py b/python/uv/_find_uv.py -index 736288a4c..306451db2 100644 +index ebe6b8d5a..e25a2e28c 100644 --- a/python/uv/_find_uv.py +++ b/python/uv/_find_uv.py @@ -35,6 +35,14 @@ def find_uv_bin() -> str: @@ -32,5 +32,5 @@ index 736288a4c..306451db2 100644 for target in targets: if not target: -- -2.50.1 +2.53.0 diff --git a/18369.patch b/18369.patch deleted file mode 100644 index d4c2e3f..0000000 --- a/18369.patch +++ /dev/null @@ -1,33 +0,0 @@ -From eb875e65ebeba1236571f92234bcc8508cb2f92f Mon Sep 17 00:00:00 2001 -From: "Benjamin A. Beasley" -Date: Sun, 8 Mar 2026 13:06:37 +0000 -Subject: [PATCH] Conditionalize two new tests on the test-pypi feature - -Both `build_backend::tool_uv_build_backend_without_build_backend` and -`build_backend::tool_uv_build_backend_wrong_build_backend` fail in -offline environments because they try to download a build backend from -PyPI. ---- - crates/uv/tests/it/build_backend.rs | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/crates/uv/tests/it/build_backend.rs b/crates/uv/tests/it/build_backend.rs -index a01705a6765c4..454f2b1ad8594 100644 ---- a/crates/uv/tests/it/build_backend.rs -+++ b/crates/uv/tests/it/build_backend.rs -@@ -1449,6 +1449,7 @@ fn build_with_all_metadata() -> Result<()> { - /// Warn for cases where `tool.uv.build-backend` is used without the corresponding build backend - /// entry. - #[test] -+#[cfg(feature = "test-pypi")] - fn tool_uv_build_backend_without_build_backend() -> Result<()> { - let context = uv_test::test_context!("3.12"); - -@@ -1512,6 +1513,7 @@ fn tool_uv_build_backend_without_build_backend() -> Result<()> { - /// Warn for cases where `tool.uv.build-backend` is used without the corresponding build backend - /// entry. - #[test] -+#[cfg(feature = "test-pypi")] - fn tool_uv_build_backend_wrong_build_backend() -> Result<()> { - let context = uv_test::test_context!("3.12"); - diff --git a/sources b/sources index b0a112d..b4f9775 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.10.9.tar.gz) = 14a6f13aa6706a6888b471ae8ca161f5f413036624b276de10a92d29a07f759d5080ea496e0229b9c89e431c370689a25a107655bc24b65fa7972411036c6dfd +SHA512 (uv-0.10.10.tar.gz) = b95ad2534ecc57f2a4e4235d632c006283cdf0ccb8c629be880f45137cbc17ed2ee3b0a6459bbedc0603ee9b044044495a67752c549daabd9e49484afc343635 diff --git a/uv.spec b/uv.spec index d833d80..5419059 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.10.9 +Version: 0.10.10 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -154,10 +154,6 @@ Source1: uv.toml # https://github.com/astral-sh/uv/issues/4451 Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch -# Conditionalize two new tests on the test-pypi feature -# https://github.com/astral-sh/uv/pull/18369 -Patch: %{url}/pull/18369.patch - # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} From a1f57b123ba1cc5fd985ad329906fde78002a225 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Tue, 17 Mar 2026 12:04:07 +0000 Subject: [PATCH 09/79] Update to 0.10.11 (close RHBZ#2448300) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 31f7a7a..9ca428a 100644 --- a/.gitignore +++ b/.gitignore @@ -198,3 +198,4 @@ /uv-0.10.8.tar.gz /uv-0.10.9.tar.gz /uv-0.10.10.tar.gz +/uv-0.10.11.tar.gz diff --git a/sources b/sources index b4f9775..d3b9e37 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.10.10.tar.gz) = b95ad2534ecc57f2a4e4235d632c006283cdf0ccb8c629be880f45137cbc17ed2ee3b0a6459bbedc0603ee9b044044495a67752c549daabd9e49484afc343635 +SHA512 (uv-0.10.11.tar.gz) = d6ae4c6b0be58505322ed6815f47b43b68e6e671a1a5c29e40e200bf2c5582f28e7714c3aed52e5314566f2ceab8fde9f316f592e43d9903b001bf048ccf9340 diff --git a/uv.spec b/uv.spec index 5419059..b229856 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.10.10 +Version: 0.10.11 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From 07f74430e59fb84e925e6d7b238f0b334a42c97c Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Fri, 20 Mar 2026 15:55:59 +0000 Subject: [PATCH 10/79] Update to 0.10.12 (close RHBZ#2449243) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 9ca428a..ed8feb5 100644 --- a/.gitignore +++ b/.gitignore @@ -199,3 +199,4 @@ /uv-0.10.9.tar.gz /uv-0.10.10.tar.gz /uv-0.10.11.tar.gz +/uv-0.10.12.tar.gz diff --git a/sources b/sources index d3b9e37..cf02155 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.10.11.tar.gz) = d6ae4c6b0be58505322ed6815f47b43b68e6e671a1a5c29e40e200bf2c5582f28e7714c3aed52e5314566f2ceab8fde9f316f592e43d9903b001bf048ccf9340 +SHA512 (uv-0.10.12.tar.gz) = e8274cd353e9964981a1befcd8c3f9533e37831f0c3288d6c7ec2232b0c1017a4a9d5fb7960e93edfabb8c7add1d1c500b0309d2e6be59164b61a4baee1ad7b8 diff --git a/uv.spec b/uv.spec index b229856..657c92e 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.10.11 +Version: 0.10.12 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From 72691a32e4711f8a44cb8aca5ec21dab983bfa11 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sat, 21 Mar 2026 07:52:10 +0000 Subject: [PATCH 11/79] Rebuilt with rust-tar 0.4.45 for CVE-2026-33056 From 52bbc80e5c42287e4bf48ca21b7b02e6897aba3b Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sat, 21 Mar 2026 20:53:40 +0000 Subject: [PATCH 12/79] =?UTF-8?q?Further=20decrease=20max.=20parallelism?= =?UTF-8?q?=20to=20avoid=20=E2=80=9Ctoo=20many=20open=20files=E2=80=9D?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit [skip changelog] --- uv.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/uv.spec b/uv.spec index 657c92e..49f602d 100644 --- a/uv.spec +++ b/uv.spec @@ -178,7 +178,7 @@ ExcludeArch: %{ix86} # Compilation may fail on builders with very many cores (e.g. 192 cores) due to # “too many open files.” Try to keep the files/core ratio from getting too low. -%global _smp_ncpus_max 96 +%global _smp_ncpus_max 72 BuildRequires: cargo-rpm-macros >= 24 BuildRequires: rust2rpm-helper From fb79c2912de6a25bdc853cded9fc170a1b2cd517 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 25 Mar 2026 15:23:45 +0000 Subject: [PATCH 13/79] Update to 0.11.2 (close RHBZ#2450582) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index ed8feb5..396e334 100644 --- a/.gitignore +++ b/.gitignore @@ -200,3 +200,4 @@ /uv-0.10.10.tar.gz /uv-0.10.11.tar.gz /uv-0.10.12.tar.gz +/uv-0.11.2.tar.gz diff --git a/sources b/sources index cf02155..1706f76 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.10.12.tar.gz) = e8274cd353e9964981a1befcd8c3f9533e37831f0c3288d6c7ec2232b0c1017a4a9d5fb7960e93edfabb8c7add1d1c500b0309d2e6be59164b61a4baee1ad7b8 +SHA512 (uv-0.11.2.tar.gz) = 5db8253e1403a21a82c172429f8a2ee336d19a7b1e640942bd8b6a523defa8308f60b035c8ffae40d1de9292a598a5619f36debf5bf7bb3663b1f630e311cfd4 diff --git a/uv.spec b/uv.spec index 49f602d..c8d3a61 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.10.12 +Version: 0.11.2 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From e113162019e49345594892519dddf121ac07f73e Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Mon, 6 Apr 2026 13:26:50 +0100 Subject: [PATCH 14/79] Update to 0.11.4 (close RHBZ#2454177) --- .gitignore | 1 + 18919.patch | 263 ++++++++++++++++++++++++++++++++++++++++++++++++++++ sources | 2 +- uv.spec | 9 +- 4 files changed, 273 insertions(+), 2 deletions(-) create mode 100644 18919.patch diff --git a/.gitignore b/.gitignore index 396e334..2852e00 100644 --- a/.gitignore +++ b/.gitignore @@ -201,3 +201,4 @@ /uv-0.10.11.tar.gz /uv-0.10.12.tar.gz /uv-0.11.2.tar.gz +/uv-0.11.4.tar.gz diff --git a/18919.patch b/18919.patch new file mode 100644 index 0000000..54026d3 --- /dev/null +++ b/18919.patch @@ -0,0 +1,263 @@ +From ac63848583324e54fcd4cce078d7f93531d9aade Mon Sep 17 00:00:00 2001 +From: Claude +Date: Wed, 8 Apr 2026 12:40:04 +0000 +Subject: [PATCH 1/4] Fix doctest failures in uv-keyring crate + +- Replace `keyring::` with `uv_keyring::` in doctests (the crate was + vendored/renamed but doc examples still referenced the old name) +- Add `#[tokio::main]` and `async fn main` to README example since + Entry methods are async, and mark it `no_run` since it needs a real + keyring backend +- Add `.await` to `set_password()` calls in mock.rs doctest and wrap + in a tokio runtime block + +Fixes astral-sh/uv#18916 + +https://claude.ai/code/session_01UJXU3iFvu9dLce56ZvNNDu +--- + crates/uv-keyring/README.md | 7 ++++--- + crates/uv-keyring/src/mock.rs | 12 +++++++----- + 2 files changed, 11 insertions(+), 8 deletions(-) + +diff --git a/crates/uv-keyring/README.md b/crates/uv-keyring/README.md +index 613bff88af70f..d8fa6d41563d0 100644 +--- a/crates/uv-keyring/README.md ++++ b/crates/uv-keyring/README.md +@@ -18,10 +18,11 @@ platform's persistent credential store.) The password or secret can then be read + `get_password` or `get_secret` methods. The underlying credential (with its password/secret data) + can then be removed using the `delete_credential` method. + +-```rust +-use keyring::{Entry, Result}; ++```rust,no_run ++use uv_keyring::{Entry, Result}; + +-fn main() -> Result<()> { ++#[tokio::main] ++async fn main() -> Result<()> { + let entry = Entry::new("my-service", "my-name")?; + entry.set_password("topS3cr3tP4$$w0rd").await?; + let password = entry.get_password().await?; +diff --git a/crates/uv-keyring/src/mock.rs b/crates/uv-keyring/src/mock.rs +index 891cb029186ad..f181e34d9c498 100644 +--- a/crates/uv-keyring/src/mock.rs ++++ b/crates/uv-keyring/src/mock.rs +@@ -10,7 +10,7 @@ in this store have no attributes at all. + To use this credential store instead of the default, make this call during + application startup _before_ creating any entries: + ```rust +-keyring::set_default_credential_builder(keyring::mock::default_credential_builder()); ++uv_keyring::set_default_credential_builder(uv_keyring::mock::default_credential_builder()); + ``` + + You can then create entries as you usually do, and call their usual methods +@@ -24,13 +24,15 @@ with the appropriate error. The next entry method called on the credential + will fail with the error you set. The error will then be cleared, so the next + call on the mock will operate as usual. Here's a complete example: + ```rust +-# use keyring::{Entry, Error, mock, mock::MockCredential}; +-# keyring::set_default_credential_builder(mock::default_credential_builder()); ++# use uv_keyring::{Entry, Error, mock, mock::MockCredential}; ++# uv_keyring::set_default_credential_builder(mock::default_credential_builder()); ++# tokio::runtime::Runtime::new().unwrap().block_on(async { + let entry = Entry::new("service", "user").unwrap(); + let mock: &MockCredential = entry.get_credential().downcast_ref().unwrap(); + mock.set_error(Error::Invalid("mock error".to_string(), "takes precedence".to_string())); +-entry.set_password("test").expect_err("error will override"); +-entry.set_password("test").expect("error has been cleared"); ++entry.set_password("test").await.expect_err("error will override"); ++entry.set_password("test").await.expect("error has been cleared"); ++# }); + ``` + */ + use std::cell::RefCell; + +From 750a4b1de0f69737abfa600d04bd72c21aeed6bc Mon Sep 17 00:00:00 2001 +From: Claude +Date: Wed, 8 Apr 2026 13:06:07 +0000 +Subject: [PATCH 2/4] Mark vendored uv-keyring doctests as ignored +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +This is an internal vendored crate — the doctests duplicate coverage +already provided by unit tests and would break again on any upstream +sync. Mark the code blocks as `ignore` so they remain as documentation +but don't run. Also remove the `doc-comment` dev-dependency and +README doctest inclusion since the README example is now ignored too. + +https://claude.ai/code/session_01UJXU3iFvu9dLce56ZvNNDu +--- + crates/uv-keyring/Cargo.toml | 1 - + crates/uv-keyring/README.md | 2 +- + crates/uv-keyring/src/lib.rs | 3 --- + crates/uv-keyring/src/mock.rs | 10 ++++------ + 4 files changed, 5 insertions(+), 11 deletions(-) + +diff --git a/crates/uv-keyring/Cargo.toml b/crates/uv-keyring/Cargo.toml +index a1339c5c1b5d0..052a7058a4be2 100644 +--- a/crates/uv-keyring/Cargo.toml ++++ b/crates/uv-keyring/Cargo.toml +@@ -40,7 +40,6 @@ windows = { workspace = true, features = ["Win32_Foundation", "Win32_Security_Cr + zeroize = { workspace = true } + + [dev-dependencies] +-doc-comment = "0.3" + env_logger = "0.11.5" + fastrand = { workspace = true } + +diff --git a/crates/uv-keyring/README.md b/crates/uv-keyring/README.md +index d8fa6d41563d0..05758a9263e39 100644 +--- a/crates/uv-keyring/README.md ++++ b/crates/uv-keyring/README.md +@@ -18,7 +18,7 @@ platform's persistent credential store.) The password or secret can then be read + `get_password` or `get_secret` methods. The underlying credential (with its password/secret data) + can then be removed using the `delete_credential` method. + +-```rust,no_run ++```rust,ignore + use uv_keyring::{Entry, Result}; + + #[tokio::main] +diff --git a/crates/uv-keyring/src/lib.rs b/crates/uv-keyring/src/lib.rs +index 07f6a92fccc10..d95867a2d24ac 100644 +--- a/crates/uv-keyring/src/lib.rs ++++ b/crates/uv-keyring/src/lib.rs +@@ -398,9 +398,6 @@ impl Entry { + } + } + +-#[cfg(doctest)] +-doc_comment::doctest!("../README.md", readme); +- + #[cfg(test)] + /// There are no actual tests in this module. + /// Instead, it contains generics that each keystore invokes in their tests, +diff --git a/crates/uv-keyring/src/mock.rs b/crates/uv-keyring/src/mock.rs +index f181e34d9c498..8aed3b839fe95 100644 +--- a/crates/uv-keyring/src/mock.rs ++++ b/crates/uv-keyring/src/mock.rs +@@ -9,7 +9,7 @@ in this store have no attributes at all. + + To use this credential store instead of the default, make this call during + application startup _before_ creating any entries: +-```rust ++```rust,ignore + uv_keyring::set_default_credential_builder(uv_keyring::mock::default_credential_builder()); + ``` + +@@ -23,16 +23,14 @@ downcast the entry to a [`MockCredential`] and then call [`set_error`](MockCrede + with the appropriate error. The next entry method called on the credential + will fail with the error you set. The error will then be cleared, so the next + call on the mock will operate as usual. Here's a complete example: +-```rust +-# use uv_keyring::{Entry, Error, mock, mock::MockCredential}; +-# uv_keyring::set_default_credential_builder(mock::default_credential_builder()); +-# tokio::runtime::Runtime::new().unwrap().block_on(async { ++```rust,ignore ++use uv_keyring::{Entry, Error, mock, mock::MockCredential}; ++uv_keyring::set_default_credential_builder(mock::default_credential_builder()); + let entry = Entry::new("service", "user").unwrap(); + let mock: &MockCredential = entry.get_credential().downcast_ref().unwrap(); + mock.set_error(Error::Invalid("mock error".to_string(), "takes precedence".to_string())); + entry.set_password("test").await.expect_err("error will override"); + entry.set_password("test").await.expect("error has been cleared"); +-# }); + ``` + */ + use std::cell::RefCell; + +From 6541710154d5a7f285ed3c1ce549d78e6a55424b Mon Sep 17 00:00:00 2001 +From: Claude +Date: Wed, 8 Apr 2026 13:06:32 +0000 +Subject: [PATCH 3/4] Update Cargo.lock after removing doc-comment dependency + +https://claude.ai/code/session_01UJXU3iFvu9dLce56ZvNNDu +--- + Cargo.lock | 1 - + 1 file changed, 1 deletion(-) + +diff --git a/Cargo.lock b/Cargo.lock +index 578d40498116c..27ee24a1c022e 100644 +--- a/Cargo.lock ++++ b/Cargo.lock +@@ -6735,7 +6735,6 @@ version = "0.0.36" + dependencies = [ + "async-trait", + "byteorder", +- "doc-comment", + "env_logger", + "fastrand", + "secret-service", + +From 0e3e9c556b216a05dcc578e3441a53607ace8c93 Mon Sep 17 00:00:00 2001 +From: Claude +Date: Wed, 8 Apr 2026 13:20:41 +0000 +Subject: [PATCH 4/4] Remove mock.rs doctest code blocks and README ignore + annotation +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +The mock.rs code blocks duplicated unit test coverage and were prone +to drifting from reality on upstream syncs — remove them entirely, +keeping the prose. The README code block doesn't need `ignore` since +the `doc_comment::doctest!` inclusion was already removed. + +https://claude.ai/code/session_01UJXU3iFvu9dLce56ZvNNDu +--- + crates/uv-keyring/README.md | 2 +- + crates/uv-keyring/src/mock.rs | 20 +++++--------------- + 2 files changed, 6 insertions(+), 16 deletions(-) + +diff --git a/crates/uv-keyring/README.md b/crates/uv-keyring/README.md +index 05758a9263e39..5b598f2f09559 100644 +--- a/crates/uv-keyring/README.md ++++ b/crates/uv-keyring/README.md +@@ -18,7 +18,7 @@ platform's persistent credential store.) The password or secret can then be read + `get_password` or `get_secret` methods. The underlying credential (with its password/secret data) + can then be removed using the `delete_credential` method. + +-```rust,ignore ++```rust + use uv_keyring::{Entry, Result}; + + #[tokio::main] +diff --git a/crates/uv-keyring/src/mock.rs b/crates/uv-keyring/src/mock.rs +index 8aed3b839fe95..ab41542d50717 100644 +--- a/crates/uv-keyring/src/mock.rs ++++ b/crates/uv-keyring/src/mock.rs +@@ -7,11 +7,10 @@ that is platform-independent, provides no persistence, and allows the client + to specify the return values (including errors) for each call. The credentials + in this store have no attributes at all. + +-To use this credential store instead of the default, make this call during +-application startup _before_ creating any entries: +-```rust,ignore +-uv_keyring::set_default_credential_builder(uv_keyring::mock::default_credential_builder()); +-``` ++To use this credential store instead of the default, call ++[`set_default_credential_builder`](crate::set_default_credential_builder) ++with [`default_credential_builder`] during application startup ++_before_ creating any entries. + + You can then create entries as you usually do, and call their usual methods + to set, get, and delete passwords. There is no persistence other than +@@ -22,16 +21,7 @@ If you want a method call on an entry to fail in a specific way, you can + downcast the entry to a [`MockCredential`] and then call [`set_error`](MockCredential::set_error) + with the appropriate error. The next entry method called on the credential + will fail with the error you set. The error will then be cleared, so the next +-call on the mock will operate as usual. Here's a complete example: +-```rust,ignore +-use uv_keyring::{Entry, Error, mock, mock::MockCredential}; +-uv_keyring::set_default_credential_builder(mock::default_credential_builder()); +-let entry = Entry::new("service", "user").unwrap(); +-let mock: &MockCredential = entry.get_credential().downcast_ref().unwrap(); +-mock.set_error(Error::Invalid("mock error".to_string(), "takes precedence".to_string())); +-entry.set_password("test").await.expect_err("error will override"); +-entry.set_password("test").await.expect("error has been cleared"); +-``` ++call on the mock will operate as usual. + */ + use std::cell::RefCell; + use std::sync::Mutex; diff --git a/sources b/sources index 1706f76..179ed45 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.2.tar.gz) = 5db8253e1403a21a82c172429f8a2ee336d19a7b1e640942bd8b6a523defa8308f60b035c8ffae40d1de9292a598a5619f36debf5bf7bb3663b1f630e311cfd4 +SHA512 (uv-0.11.4.tar.gz) = 84fb4d49147bf23bbe338571883c31370841a011f9ad6a15219e8699169fce5e82c2740159ef3c998ad2d4ef463dc6a398df93e82788a0bdccc68a15e36b3e65 diff --git a/uv.spec b/uv.spec index c8d3a61..addcd6b 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.2 +Version: 0.11.4 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -154,6 +154,13 @@ Source1: uv.toml # https://github.com/astral-sh/uv/issues/4451 Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch +# Remove doctests from uv-keyring +# https://github.com/astral-sh/uv/pull/18919 +# Fixes: +# Some issues with doctests in the uv_keyring crate +# https://github.com/astral-sh/uv/issues/18916 +Patch: %{url}/pull/18919.patch + # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} From ff58ad585abf58c5c519c16432dc153de67b9b06 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 9 Apr 2026 11:48:33 +0100 Subject: [PATCH 15/79] Update to 0.11.5 (close RHBZ#2454177) --- .gitignore | 1 + 18919.patch | 263 ---------------------------------------------------- sources | 2 +- uv.spec | 10 +- 4 files changed, 3 insertions(+), 273 deletions(-) delete mode 100644 18919.patch diff --git a/.gitignore b/.gitignore index 2852e00..2e6a668 100644 --- a/.gitignore +++ b/.gitignore @@ -202,3 +202,4 @@ /uv-0.10.12.tar.gz /uv-0.11.2.tar.gz /uv-0.11.4.tar.gz +/uv-0.11.5.tar.gz diff --git a/18919.patch b/18919.patch deleted file mode 100644 index 54026d3..0000000 --- a/18919.patch +++ /dev/null @@ -1,263 +0,0 @@ -From ac63848583324e54fcd4cce078d7f93531d9aade Mon Sep 17 00:00:00 2001 -From: Claude -Date: Wed, 8 Apr 2026 12:40:04 +0000 -Subject: [PATCH 1/4] Fix doctest failures in uv-keyring crate - -- Replace `keyring::` with `uv_keyring::` in doctests (the crate was - vendored/renamed but doc examples still referenced the old name) -- Add `#[tokio::main]` and `async fn main` to README example since - Entry methods are async, and mark it `no_run` since it needs a real - keyring backend -- Add `.await` to `set_password()` calls in mock.rs doctest and wrap - in a tokio runtime block - -Fixes astral-sh/uv#18916 - -https://claude.ai/code/session_01UJXU3iFvu9dLce56ZvNNDu ---- - crates/uv-keyring/README.md | 7 ++++--- - crates/uv-keyring/src/mock.rs | 12 +++++++----- - 2 files changed, 11 insertions(+), 8 deletions(-) - -diff --git a/crates/uv-keyring/README.md b/crates/uv-keyring/README.md -index 613bff88af70f..d8fa6d41563d0 100644 ---- a/crates/uv-keyring/README.md -+++ b/crates/uv-keyring/README.md -@@ -18,10 +18,11 @@ platform's persistent credential store.) The password or secret can then be read - `get_password` or `get_secret` methods. The underlying credential (with its password/secret data) - can then be removed using the `delete_credential` method. - --```rust --use keyring::{Entry, Result}; -+```rust,no_run -+use uv_keyring::{Entry, Result}; - --fn main() -> Result<()> { -+#[tokio::main] -+async fn main() -> Result<()> { - let entry = Entry::new("my-service", "my-name")?; - entry.set_password("topS3cr3tP4$$w0rd").await?; - let password = entry.get_password().await?; -diff --git a/crates/uv-keyring/src/mock.rs b/crates/uv-keyring/src/mock.rs -index 891cb029186ad..f181e34d9c498 100644 ---- a/crates/uv-keyring/src/mock.rs -+++ b/crates/uv-keyring/src/mock.rs -@@ -10,7 +10,7 @@ in this store have no attributes at all. - To use this credential store instead of the default, make this call during - application startup _before_ creating any entries: - ```rust --keyring::set_default_credential_builder(keyring::mock::default_credential_builder()); -+uv_keyring::set_default_credential_builder(uv_keyring::mock::default_credential_builder()); - ``` - - You can then create entries as you usually do, and call their usual methods -@@ -24,13 +24,15 @@ with the appropriate error. The next entry method called on the credential - will fail with the error you set. The error will then be cleared, so the next - call on the mock will operate as usual. Here's a complete example: - ```rust --# use keyring::{Entry, Error, mock, mock::MockCredential}; --# keyring::set_default_credential_builder(mock::default_credential_builder()); -+# use uv_keyring::{Entry, Error, mock, mock::MockCredential}; -+# uv_keyring::set_default_credential_builder(mock::default_credential_builder()); -+# tokio::runtime::Runtime::new().unwrap().block_on(async { - let entry = Entry::new("service", "user").unwrap(); - let mock: &MockCredential = entry.get_credential().downcast_ref().unwrap(); - mock.set_error(Error::Invalid("mock error".to_string(), "takes precedence".to_string())); --entry.set_password("test").expect_err("error will override"); --entry.set_password("test").expect("error has been cleared"); -+entry.set_password("test").await.expect_err("error will override"); -+entry.set_password("test").await.expect("error has been cleared"); -+# }); - ``` - */ - use std::cell::RefCell; - -From 750a4b1de0f69737abfa600d04bd72c21aeed6bc Mon Sep 17 00:00:00 2001 -From: Claude -Date: Wed, 8 Apr 2026 13:06:07 +0000 -Subject: [PATCH 2/4] Mark vendored uv-keyring doctests as ignored -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This is an internal vendored crate — the doctests duplicate coverage -already provided by unit tests and would break again on any upstream -sync. Mark the code blocks as `ignore` so they remain as documentation -but don't run. Also remove the `doc-comment` dev-dependency and -README doctest inclusion since the README example is now ignored too. - -https://claude.ai/code/session_01UJXU3iFvu9dLce56ZvNNDu ---- - crates/uv-keyring/Cargo.toml | 1 - - crates/uv-keyring/README.md | 2 +- - crates/uv-keyring/src/lib.rs | 3 --- - crates/uv-keyring/src/mock.rs | 10 ++++------ - 4 files changed, 5 insertions(+), 11 deletions(-) - -diff --git a/crates/uv-keyring/Cargo.toml b/crates/uv-keyring/Cargo.toml -index a1339c5c1b5d0..052a7058a4be2 100644 ---- a/crates/uv-keyring/Cargo.toml -+++ b/crates/uv-keyring/Cargo.toml -@@ -40,7 +40,6 @@ windows = { workspace = true, features = ["Win32_Foundation", "Win32_Security_Cr - zeroize = { workspace = true } - - [dev-dependencies] --doc-comment = "0.3" - env_logger = "0.11.5" - fastrand = { workspace = true } - -diff --git a/crates/uv-keyring/README.md b/crates/uv-keyring/README.md -index d8fa6d41563d0..05758a9263e39 100644 ---- a/crates/uv-keyring/README.md -+++ b/crates/uv-keyring/README.md -@@ -18,7 +18,7 @@ platform's persistent credential store.) The password or secret can then be read - `get_password` or `get_secret` methods. The underlying credential (with its password/secret data) - can then be removed using the `delete_credential` method. - --```rust,no_run -+```rust,ignore - use uv_keyring::{Entry, Result}; - - #[tokio::main] -diff --git a/crates/uv-keyring/src/lib.rs b/crates/uv-keyring/src/lib.rs -index 07f6a92fccc10..d95867a2d24ac 100644 ---- a/crates/uv-keyring/src/lib.rs -+++ b/crates/uv-keyring/src/lib.rs -@@ -398,9 +398,6 @@ impl Entry { - } - } - --#[cfg(doctest)] --doc_comment::doctest!("../README.md", readme); -- - #[cfg(test)] - /// There are no actual tests in this module. - /// Instead, it contains generics that each keystore invokes in their tests, -diff --git a/crates/uv-keyring/src/mock.rs b/crates/uv-keyring/src/mock.rs -index f181e34d9c498..8aed3b839fe95 100644 ---- a/crates/uv-keyring/src/mock.rs -+++ b/crates/uv-keyring/src/mock.rs -@@ -9,7 +9,7 @@ in this store have no attributes at all. - - To use this credential store instead of the default, make this call during - application startup _before_ creating any entries: --```rust -+```rust,ignore - uv_keyring::set_default_credential_builder(uv_keyring::mock::default_credential_builder()); - ``` - -@@ -23,16 +23,14 @@ downcast the entry to a [`MockCredential`] and then call [`set_error`](MockCrede - with the appropriate error. The next entry method called on the credential - will fail with the error you set. The error will then be cleared, so the next - call on the mock will operate as usual. Here's a complete example: --```rust --# use uv_keyring::{Entry, Error, mock, mock::MockCredential}; --# uv_keyring::set_default_credential_builder(mock::default_credential_builder()); --# tokio::runtime::Runtime::new().unwrap().block_on(async { -+```rust,ignore -+use uv_keyring::{Entry, Error, mock, mock::MockCredential}; -+uv_keyring::set_default_credential_builder(mock::default_credential_builder()); - let entry = Entry::new("service", "user").unwrap(); - let mock: &MockCredential = entry.get_credential().downcast_ref().unwrap(); - mock.set_error(Error::Invalid("mock error".to_string(), "takes precedence".to_string())); - entry.set_password("test").await.expect_err("error will override"); - entry.set_password("test").await.expect("error has been cleared"); --# }); - ``` - */ - use std::cell::RefCell; - -From 6541710154d5a7f285ed3c1ce549d78e6a55424b Mon Sep 17 00:00:00 2001 -From: Claude -Date: Wed, 8 Apr 2026 13:06:32 +0000 -Subject: [PATCH 3/4] Update Cargo.lock after removing doc-comment dependency - -https://claude.ai/code/session_01UJXU3iFvu9dLce56ZvNNDu ---- - Cargo.lock | 1 - - 1 file changed, 1 deletion(-) - -diff --git a/Cargo.lock b/Cargo.lock -index 578d40498116c..27ee24a1c022e 100644 ---- a/Cargo.lock -+++ b/Cargo.lock -@@ -6735,7 +6735,6 @@ version = "0.0.36" - dependencies = [ - "async-trait", - "byteorder", -- "doc-comment", - "env_logger", - "fastrand", - "secret-service", - -From 0e3e9c556b216a05dcc578e3441a53607ace8c93 Mon Sep 17 00:00:00 2001 -From: Claude -Date: Wed, 8 Apr 2026 13:20:41 +0000 -Subject: [PATCH 4/4] Remove mock.rs doctest code blocks and README ignore - annotation -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -The mock.rs code blocks duplicated unit test coverage and were prone -to drifting from reality on upstream syncs — remove them entirely, -keeping the prose. The README code block doesn't need `ignore` since -the `doc_comment::doctest!` inclusion was already removed. - -https://claude.ai/code/session_01UJXU3iFvu9dLce56ZvNNDu ---- - crates/uv-keyring/README.md | 2 +- - crates/uv-keyring/src/mock.rs | 20 +++++--------------- - 2 files changed, 6 insertions(+), 16 deletions(-) - -diff --git a/crates/uv-keyring/README.md b/crates/uv-keyring/README.md -index 05758a9263e39..5b598f2f09559 100644 ---- a/crates/uv-keyring/README.md -+++ b/crates/uv-keyring/README.md -@@ -18,7 +18,7 @@ platform's persistent credential store.) The password or secret can then be read - `get_password` or `get_secret` methods. The underlying credential (with its password/secret data) - can then be removed using the `delete_credential` method. - --```rust,ignore -+```rust - use uv_keyring::{Entry, Result}; - - #[tokio::main] -diff --git a/crates/uv-keyring/src/mock.rs b/crates/uv-keyring/src/mock.rs -index 8aed3b839fe95..ab41542d50717 100644 ---- a/crates/uv-keyring/src/mock.rs -+++ b/crates/uv-keyring/src/mock.rs -@@ -7,11 +7,10 @@ that is platform-independent, provides no persistence, and allows the client - to specify the return values (including errors) for each call. The credentials - in this store have no attributes at all. - --To use this credential store instead of the default, make this call during --application startup _before_ creating any entries: --```rust,ignore --uv_keyring::set_default_credential_builder(uv_keyring::mock::default_credential_builder()); --``` -+To use this credential store instead of the default, call -+[`set_default_credential_builder`](crate::set_default_credential_builder) -+with [`default_credential_builder`] during application startup -+_before_ creating any entries. - - You can then create entries as you usually do, and call their usual methods - to set, get, and delete passwords. There is no persistence other than -@@ -22,16 +21,7 @@ If you want a method call on an entry to fail in a specific way, you can - downcast the entry to a [`MockCredential`] and then call [`set_error`](MockCredential::set_error) - with the appropriate error. The next entry method called on the credential - will fail with the error you set. The error will then be cleared, so the next --call on the mock will operate as usual. Here's a complete example: --```rust,ignore --use uv_keyring::{Entry, Error, mock, mock::MockCredential}; --uv_keyring::set_default_credential_builder(mock::default_credential_builder()); --let entry = Entry::new("service", "user").unwrap(); --let mock: &MockCredential = entry.get_credential().downcast_ref().unwrap(); --mock.set_error(Error::Invalid("mock error".to_string(), "takes precedence".to_string())); --entry.set_password("test").await.expect_err("error will override"); --entry.set_password("test").await.expect("error has been cleared"); --``` -+call on the mock will operate as usual. - */ - use std::cell::RefCell; - use std::sync::Mutex; diff --git a/sources b/sources index 179ed45..729cb04 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.4.tar.gz) = 84fb4d49147bf23bbe338571883c31370841a011f9ad6a15219e8699169fce5e82c2740159ef3c998ad2d4ef463dc6a398df93e82788a0bdccc68a15e36b3e65 +SHA512 (uv-0.11.5.tar.gz) = ade88d151b3da1a73dbd43b6b9c27722822f61e7088a53dfc1a073436350705468b37ebd301eaa5ddb2fdcd39978096b2c95180c735bc49c4a07391ca3bd4c09 diff --git a/uv.spec b/uv.spec index addcd6b..2afe1df 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.4 +Version: 0.11.5 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -154,13 +154,6 @@ Source1: uv.toml # https://github.com/astral-sh/uv/issues/4451 Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch -# Remove doctests from uv-keyring -# https://github.com/astral-sh/uv/pull/18919 -# Fixes: -# Some issues with doctests in the uv_keyring crate -# https://github.com/astral-sh/uv/issues/18916 -Patch: %{url}/pull/18919.patch - # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} @@ -633,7 +626,6 @@ skip="${skip-} --skip base_client::tests::retried_status_codes" %license LICENSE-APACHE LICENSE-MIT LICENSE.dependencies LICENSE.bundled/ %doc CHANGELOG.md %doc README.md -%doc PIP_COMPATIBILITY.md %{_bindir}/uv # Equivalent to “uv tool run”: From 5c347689ee65f5daeaca0371d83a5bb995a0ed8c Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 9 Apr 2026 14:14:24 +0100 Subject: [PATCH 16/79] Skip three tests that fail only on ppc64le --- uv.spec | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/uv.spec b/uv.spec index 2afe1df..69e1424 100644 --- a/uv.spec +++ b/uv.spec @@ -616,6 +616,23 @@ skip="${skip-} --skip tests::built_by_uv_building" # dependency version differing from Cargo.lock. skip="${skip-} --skip base_client::tests::retried_status_codes" +%ifarch %{power64} +# TODO: Why do these seem to fail only on ppc64le? Are the failures 100% +# reproducible, or are they flaky? Can we reproduce in a git checkout and +# report upstream? Is this a race condition that disappears on cargo nextest, +# with its process isolation? +# +# Error: failed to build HTTP client +# Caused by: +# 0: certificate in `/tmp/uv/tests/certs/.tmpFF0lkk/ca.pem` (from +# `SSL_CERT_FILE`) could not be used as a trust anchor on certificate +# `CN=uv-test-ca, O=Astral Software Inc.` +# 1: ExtensionValueInvalid +skip="${skip-} --skip user_agent_version::test_user_agent_has_linehaul" +skip="${skip-} --skip user_agent_version::test_user_agent_has_subcommand" +skip="${skip-} --skip user_agent_version::test_user_agent_has_version" +%endif + %cargo_test -- -- --exact ${skip-} %endif From 07238fb8d4f9380439c1b3a9b7ac84638b2d7639 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 9 Apr 2026 15:23:42 +0100 Subject: [PATCH 17/79] Update to 0.11.6 (close RHBZ#2454177) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 2e6a668..4d93cbb 100644 --- a/.gitignore +++ b/.gitignore @@ -203,3 +203,4 @@ /uv-0.11.2.tar.gz /uv-0.11.4.tar.gz /uv-0.11.5.tar.gz +/uv-0.11.6.tar.gz diff --git a/sources b/sources index 729cb04..2a97a14 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.5.tar.gz) = ade88d151b3da1a73dbd43b6b9c27722822f61e7088a53dfc1a073436350705468b37ebd301eaa5ddb2fdcd39978096b2c95180c735bc49c4a07391ca3bd4c09 +SHA512 (uv-0.11.6.tar.gz) = 3f370f98b253dd84706f1724155ba4ed5cafb41b612fa75151aef26dd4f18c85f59d93c5bbddae1c59ea594fdc88857d005b6e8728cdd24f5b37b99ba4ef32cd diff --git a/uv.spec b/uv.spec index 69e1424..6c60285 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.5 +Version: 0.11.6 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From 8aee0b86aee3ae2dc8431bf5a56a3e486930e02a Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 9 Apr 2026 18:51:01 +0100 Subject: [PATCH 18/79] Skip user_agent_version:: tests on all architectures --- uv.spec | 25 ++++++++++++------------- 1 file changed, 12 insertions(+), 13 deletions(-) diff --git a/uv.spec b/uv.spec index 6c60285..189466a 100644 --- a/uv.spec +++ b/uv.spec @@ -616,22 +616,21 @@ skip="${skip-} --skip tests::built_by_uv_building" # dependency version differing from Cargo.lock. skip="${skip-} --skip base_client::tests::retried_status_codes" -%ifarch %{power64} -# TODO: Why do these seem to fail only on ppc64le? Are the failures 100% -# reproducible, or are they flaky? Can we reproduce in a git checkout and -# report upstream? Is this a race condition that disappears on cargo nextest, -# with its process isolation? -# -# Error: failed to build HTTP client -# Caused by: -# 0: certificate in `/tmp/uv/tests/certs/.tmpFF0lkk/ca.pem` (from -# `SSL_CERT_FILE`) could not be used as a trust anchor on certificate -# `CN=uv-test-ca, O=Astral Software Inc.` -# 1: ExtensionValueInvalid +# These fail flakily: most frequently on ppc64le, but this seems to be just a +# matter of luck, since we suspect a race condition. We have also seen failures +# on aarch64. This is probably a race involving the SSL_CERT_FILE environment +# variable, which process-isolated testing in “cargo nextest” (used by +# upstream) should avoid. That suggests there is nothing to report upstream. +# When this fails, the error looks something like: +# Error: failed to build HTTP client +# Caused by: +# 0: certificate in `/tmp/uv/tests/certs/.tmpFF0lkk/ca.pem` (from +# `SSL_CERT_FILE`) could not be used as a trust anchor on certificate +# `CN=uv-test-ca, O=Astral Software Inc.` +# 1: ExtensionValueInvalid skip="${skip-} --skip user_agent_version::test_user_agent_has_linehaul" skip="${skip-} --skip user_agent_version::test_user_agent_has_subcommand" skip="${skip-} --skip user_agent_version::test_user_agent_has_version" -%endif %cargo_test -- -- --exact ${skip-} %endif From 49ae3ae921b77f3410cea12d127085e60b4c7a71 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 16 Apr 2026 11:36:35 +0100 Subject: [PATCH 19/79] Update to 0.11.7 (close RHBZ#2458860) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 4d93cbb..589f69c 100644 --- a/.gitignore +++ b/.gitignore @@ -204,3 +204,4 @@ /uv-0.11.4.tar.gz /uv-0.11.5.tar.gz /uv-0.11.6.tar.gz +/uv-0.11.7.tar.gz diff --git a/sources b/sources index 2a97a14..d0b4cc9 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.6.tar.gz) = 3f370f98b253dd84706f1724155ba4ed5cafb41b612fa75151aef26dd4f18c85f59d93c5bbddae1c59ea594fdc88857d005b6e8728cdd24f5b37b99ba4ef32cd +SHA512 (uv-0.11.7.tar.gz) = f9b34b628ac035cacb36bd9cd7276d28c59f768360a197f4c1c036a81651aa6c40b17656c4b5230cc19b496c415687fc99f05bf4c66459e5457f5cef105b8d7e diff --git a/uv.spec b/uv.spec index 189466a..30408cd 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.6 +Version: 0.11.7 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From b70f3fd0f1ee28e43973b2255ddff3ed695e5343 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Tue, 5 May 2026 09:41:14 +0100 Subject: [PATCH 20/79] Update to 0.11.9 (close RHBZ#2466654) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 589f69c..14d9d18 100644 --- a/.gitignore +++ b/.gitignore @@ -205,3 +205,4 @@ /uv-0.11.5.tar.gz /uv-0.11.6.tar.gz /uv-0.11.7.tar.gz +/uv-0.11.9.tar.gz diff --git a/sources b/sources index d0b4cc9..534b594 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.7.tar.gz) = f9b34b628ac035cacb36bd9cd7276d28c59f768360a197f4c1c036a81651aa6c40b17656c4b5230cc19b496c415687fc99f05bf4c66459e5457f5cef105b8d7e +SHA512 (uv-0.11.9.tar.gz) = 821ef460b68fa9d3d7040633903f57b6108ff766ec2ac55369e19762cb3a8903ab8d1611cf2866dc072741d363a75e1a9867dbbd3be2fe0ee967088309de42d2 diff --git a/uv.spec b/uv.spec index 30408cd..d8a191f 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.7 +Version: 0.11.9 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From 31529805d730030f7ee620b20c93d4f29577d0d8 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Tue, 5 May 2026 11:17:18 +0100 Subject: [PATCH 21/79] Rebuilt with astral-tokio-tar 0.6.1 - Fixes GHSA-xx64-wwv2-hcqq; fixes GHSA-fp55-jw48-c537. From d6defe2f8145ca3fde1bcae4015224ff04e9acdd Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 6 May 2026 10:32:02 +0100 Subject: [PATCH 22/79] Update to 0.11.10 (close RHBZ#2466908) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 14d9d18..35a6b63 100644 --- a/.gitignore +++ b/.gitignore @@ -206,3 +206,4 @@ /uv-0.11.6.tar.gz /uv-0.11.7.tar.gz /uv-0.11.9.tar.gz +/uv-0.11.10.tar.gz diff --git a/sources b/sources index 534b594..8c98de0 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.9.tar.gz) = 821ef460b68fa9d3d7040633903f57b6108ff766ec2ac55369e19762cb3a8903ab8d1611cf2866dc072741d363a75e1a9867dbbd3be2fe0ee967088309de42d2 +SHA512 (uv-0.11.10.tar.gz) = d969396c1cf0793a4589aa8c9c47b100d3e1ca8bdd55bd95f3bdbd1164c67f58678c06190f35e22248d173f6ddc2b24cbae8c5888f44dd2cc6a1a7e1f0eeea16 diff --git a/uv.spec b/uv.spec index d8a191f..ba3e5a8 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.9 +Version: 0.11.10 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From 8f3f2413f81b831e82da99e91526f53545e06d65 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Fri, 8 May 2026 20:31:01 +0100 Subject: [PATCH 23/79] Update to 0.11.11 (close RHBZ#2466908) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 35a6b63..5b782d0 100644 --- a/.gitignore +++ b/.gitignore @@ -207,3 +207,4 @@ /uv-0.11.7.tar.gz /uv-0.11.9.tar.gz /uv-0.11.10.tar.gz +/uv-0.11.11.tar.gz diff --git a/sources b/sources index 8c98de0..3baf061 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.10.tar.gz) = d969396c1cf0793a4589aa8c9c47b100d3e1ca8bdd55bd95f3bdbd1164c67f58678c06190f35e22248d173f6ddc2b24cbae8c5888f44dd2cc6a1a7e1f0eeea16 +SHA512 (uv-0.11.11.tar.gz) = f9129868fb8d343d63e4080deb0e71e71fdb5c71e2ea4f17d05d0f0c20338daf86f521895e8bd69795ffad36ddc94e8cf5ee8fbbb4eb5fdc0692524b21eef9c6 diff --git a/uv.spec b/uv.spec index ba3e5a8..cd80104 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.10 +Version: 0.11.11 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From e062fedb2557ee2701757ca20934a0b63513c30b Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sat, 9 May 2026 07:57:53 +0100 Subject: [PATCH 24/79] Update to 0.11.12 (close RHBZ#2466908) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 5b782d0..6ed9e79 100644 --- a/.gitignore +++ b/.gitignore @@ -208,3 +208,4 @@ /uv-0.11.9.tar.gz /uv-0.11.10.tar.gz /uv-0.11.11.tar.gz +/uv-0.11.12.tar.gz diff --git a/sources b/sources index 3baf061..4efc084 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.11.tar.gz) = f9129868fb8d343d63e4080deb0e71e71fdb5c71e2ea4f17d05d0f0c20338daf86f521895e8bd69795ffad36ddc94e8cf5ee8fbbb4eb5fdc0692524b21eef9c6 +SHA512 (uv-0.11.12.tar.gz) = a23c95152f0515645174b85ed8887fe29e3e56d457aaad7992cfe5a59b95e527348ebd7e0ce9d23cf589f20849326a876ae61ed9b10324a48b8021077cd264fe diff --git a/uv.spec b/uv.spec index cd80104..8d877cd 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.11 +Version: 0.11.12 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From abe2796638e25b58a1557dcf3724126c36c34bd7 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 13 May 2026 06:59:34 +0100 Subject: [PATCH 25/79] Update to 0.11.14 (close RHBZ#2468985) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 6ed9e79..8384ce4 100644 --- a/.gitignore +++ b/.gitignore @@ -209,3 +209,4 @@ /uv-0.11.10.tar.gz /uv-0.11.11.tar.gz /uv-0.11.12.tar.gz +/uv-0.11.14.tar.gz diff --git a/sources b/sources index 4efc084..a87e948 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.12.tar.gz) = a23c95152f0515645174b85ed8887fe29e3e56d457aaad7992cfe5a59b95e527348ebd7e0ce9d23cf589f20849326a876ae61ed9b10324a48b8021077cd264fe +SHA512 (uv-0.11.14.tar.gz) = 375efa7d4afb3128e5d833f91d9fe91439d0c45c607996dae0cf25bf9b8d1a164858dccd00875020b88377fffecabb6afab8353ef0b7e393c83d64ed2320d3c2 diff --git a/uv.spec b/uv.spec index 8d877cd..d17ee23 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.12 +Version: 0.11.14 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From 9fc89f6aed9b7e990866a349c202bee2fbf3d6f2 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Mon, 18 May 2026 22:57:01 +0100 Subject: [PATCH 26/79] Update to 0.11.15 (close RHBZ#2479704) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 8384ce4..31acb14 100644 --- a/.gitignore +++ b/.gitignore @@ -210,3 +210,4 @@ /uv-0.11.11.tar.gz /uv-0.11.12.tar.gz /uv-0.11.14.tar.gz +/uv-0.11.15.tar.gz diff --git a/sources b/sources index a87e948..80756c5 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.14.tar.gz) = 375efa7d4afb3128e5d833f91d9fe91439d0c45c607996dae0cf25bf9b8d1a164858dccd00875020b88377fffecabb6afab8353ef0b7e393c83d64ed2320d3c2 +SHA512 (uv-0.11.15.tar.gz) = af427dfeaa1112642c46812f8b5a3b0b56e00fe5d308f3c5d59aa18a6e14f24254ea3041b6605967f742dd11ac85833c08d7552fb8de4bc4e8f8832e39236d7c diff --git a/uv.spec b/uv.spec index d17ee23..b7f2339 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.14 +Version: 0.11.15 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From ebdfcdd7a3d10bc222e62266576a3abf2f9ef70a Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Fri, 22 May 2026 07:09:52 +0100 Subject: [PATCH 27/79] Update to 0.11.16 (close RHBZ#2480652) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 31acb14..f77cfbc 100644 --- a/.gitignore +++ b/.gitignore @@ -211,3 +211,4 @@ /uv-0.11.12.tar.gz /uv-0.11.14.tar.gz /uv-0.11.15.tar.gz +/uv-0.11.16.tar.gz diff --git a/sources b/sources index 80756c5..b60061c 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.15.tar.gz) = af427dfeaa1112642c46812f8b5a3b0b56e00fe5d308f3c5d59aa18a6e14f24254ea3041b6605967f742dd11ac85833c08d7552fb8de4bc4e8f8832e39236d7c +SHA512 (uv-0.11.16.tar.gz) = c830b9808eeedbfdcbc8ee75ba978f9309b89f1740aa3d363cc661c42ea066b87d3d21c8cc4ccf215e8233ea3b4c2669537ffe5955cf68adf7367755428618bc diff --git a/uv.spec b/uv.spec index b7f2339..5651589 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.15 +Version: 0.11.16 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From ca4d748c96c171a54118c25ffc3b0d37a2185137 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sun, 24 May 2026 09:49:22 +0100 Subject: [PATCH 28/79] Use various long options --- uv.spec | 41 ++++++++++++++++++++++++----------------- 1 file changed, 24 insertions(+), 17 deletions(-) diff --git a/uv.spec b/uv.spec index 5651589..22a774a 100644 --- a/uv.spec +++ b/uv.spec @@ -352,28 +352,32 @@ This package provides an importable Python module for uv. %autosetup -p1 # Collect license files of vendored dependencies in the main source archive -install -t LICENSE.bundled/packaging -D -p -m 0644 \ +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/packaging \ crates/uv-python/python/packaging/LICENSE.* -install -t LICENSE.bundled/pep440_rs -D -p -m 0644 crates/uv-pep440/License-* -install -t LICENSE.bundled/pep508_rs -D -p -m 0644 crates/uv-pep508/License-* -install -t LICENSE.bundled/pipreqs -D -p -m 0644 \ +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/pep440_rs crates/uv-pep440/License-* +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/pep508_rs crates/uv-pep508/License-* +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/pipreqs \ crates/uv-build-frontend/src/pipreqs/LICENSE -install -t LICENSE.bundled/ripunzip -D -p -m 0644 \ - crates/uv-extract/src/vendor/LICENSE +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/ripunzip crates/uv-extract/src/vendor/LICENSE # The original license text from rattler_installs_packages is present in a # comment, but we want it in a separate file so we can ensure it is present in # the binary RPM. -install -d LICENSE.bundled/rattler_installs_packages +install --directory LICENSE.bundled/rattler_installs_packages awk '$2 == "BSD" { out=1 }; $2 == "```" { out=0 }; out' \ crates/uv-client/src/remote_metadata.rs | - sed -r 's@^///( |$)@@' | + sed --regexp-extended 's@^///( |$)@@' | tee LICENSE.bundled/rattler_installs_packages/LICENSE # Similarly for virtualenv. All files in # crates/uv-virtualenv/src/activator/activate/ have the same license text. -install -d LICENSE.bundled/virtualenv +install --directory LICENSE.bundled/virtualenv awk '$1 == "#" { out=1 }; $1 != "#" { out=0; exit }; out' \ crates/uv-virtualenv/src/activator/activate | - sed -r 's@^#( |$)@@' | + sed --regexp-extended 's@^#( |$)@@' | tee LICENSE.bundled/virtualenv/LICENSE # Patch out foreign (e.g. Windows-only) dependencies. Follow symbolic links so @@ -387,20 +391,20 @@ find -L . -type f -name Cargo.toml -print \ # the uv-trampoline-builder crate. We must remove them to prove they are not # used in the build. Since they are used only on Windows, nothing is lost by # doing so. -rm -v crates/uv-trampoline-builder/trampolines/*.exe +rm --verbose crates/uv-trampoline-builder/trampolines/*.exe # Per Cargo.toml, uv-trampoline is excluded from the workspace and not compiled # because it still requires a nightly compiler. For now, we remove it entirely # to show that we do not need to document bundling from posy. Note that we # *cannot* cleanly remove uv-trampoline-builder, only the precompiled # trampolines themselves. -rm -rv crates/uv-trampoline +rm --recursive --verbose crates/uv-trampoline # Remove the dependency on embed-manifest, which applies only when (cross-?) # compiling for Windows. tomcli set Cargo.toml del workspace.dependencies.embed-manifest # We may have to do something more sophisticated if this build script ever # starts to do anything other than just embedding a manifest on Windows. -rm -v crates/uv/build.rs +rm --verbose crates/uv/build.rs tomcli set crates/uv/Cargo.toml del build-dependencies.embed-manifest # The embed-manifest depenency is also used in uv-trampoline, which we removed. @@ -468,7 +472,8 @@ mods="${mods-}${mods+|}venv" mods="${mods-}${mods+|}version" mods="${mods-}${mods+|}workspace" comment='Downstream-only: skip, needs specific Python interpreter versions' -sed -r -i "s@mod (${mods});@// ${comment}\n#[cfg(any())]\n&@" \ +sed --regexp-extended --in-place \ + "s@mod (${mods});@// ${comment}\n#[cfg(any())]\n&@" \ crates/uv/tests/it/main.rs %endif @@ -526,9 +531,10 @@ then # library is actually pure-Python, and the python3-uv subpackage can be # noarch. We can’t tell maturin to install to the appropriate site-packages # directory, but we can fix the installation path manually. - install -d %{buildroot}%{python3_sitelib} + install --directory %{buildroot}%{python3_sitelib} mv %{buildroot}%{python3_sitearch}/uv* %{buildroot}%{python3_sitelib} - sed -r -i 's@%{python3_sitearch}@%{python3_sitelib}@' %{pyproject_files} + sed --regexp-extended --in-place \ + 's@%{python3_sitearch}@%{python3_sitelib}@' %{pyproject_files} fi # generate and install shell completions @@ -544,7 +550,8 @@ do done # Install a default system-wide configuration file -install -t '%{buildroot}%{_sysconfdir}/uv' -p -m 0644 -D '%{SOURCE1}' +install -D --preserve-timestamps --mode=0644 \ + --target='%{buildroot}%{_sysconfdir}/uv' '%{SOURCE1}' %check From 42a538d8918b0e0763a5900cd0713f1941af0e13 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 3 Jun 2026 14:08:54 +0100 Subject: [PATCH 29/79] Update to 0.11.18 (close RHBZ#2483122) --- .gitignore | 1 + sources | 2 +- uv.spec | 12 +++++++++++- 3 files changed, 13 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index f77cfbc..2bba8e8 100644 --- a/.gitignore +++ b/.gitignore @@ -212,3 +212,4 @@ /uv-0.11.14.tar.gz /uv-0.11.15.tar.gz /uv-0.11.16.tar.gz +/uv-0.11.18.tar.gz diff --git a/sources b/sources index b60061c..4415a51 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.16.tar.gz) = c830b9808eeedbfdcbc8ee75ba978f9309b89f1740aa3d363cc661c42ea066b87d3d21c8cc4ccf215e8233ea3b4c2669537ffe5955cf68adf7367755428618bc +SHA512 (uv-0.11.18.tar.gz) = 59ef43479bee5cc36dc5966ef5ec7bacb22e17d831ee2a0f8246d73c432cd0da76d230882afc08b31b610f92c333547285af420597f3f696a8acc30107cb2141 diff --git a/uv.spec b/uv.spec index 22a774a..30e9bb9 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.16 +Version: 0.11.18 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -639,6 +639,16 @@ skip="${skip-} --skip user_agent_version::test_user_agent_has_linehaul" skip="${skip-} --skip user_agent_version::test_user_agent_has_subcommand" skip="${skip-} --skip user_agent_version::test_user_agent_has_version" +# Some tests for “uv check” introduced in 0.11.18 require network access +# https://github.com/astral-sh/uv/issues/19658 +skip="${skip-} --skip check::check_missing_pyproject_toml" +skip="${skip-} --skip check::check_no_project" +skip="${skip-} --skip check::check_project" +skip="${skip-} --skip check::check_ty_version_no_match" +skip="${skip-} --skip check::check_ty_version_pinned_verbose" +skip="${skip-} --skip check::check_type_error" +skip="${skip-} --skip check::check_with_undeclared_dependency" + %cargo_test -- -- --exact ${skip-} %endif From a3a0dee7aa1a400294ee61679166a19c6017bebb Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 3 Jun 2026 19:11:51 +0100 Subject: [PATCH 30/79] Backport upstream fix for skipping uv check tests when offline --- 19661.patch | 52 ++++++++++++++++++++++++++++++++++++++++++++++++++++ uv.spec | 14 ++++---------- 2 files changed, 56 insertions(+), 10 deletions(-) create mode 100644 19661.patch diff --git a/19661.patch b/19661.patch new file mode 100644 index 0000000..72c1f1e --- /dev/null +++ b/19661.patch @@ -0,0 +1,52 @@ +From e1abeab3147489e3d1d7385d6973cabd33d81ff6 Mon Sep 17 00:00:00 2001 +From: Aria Desires +Date: Wed, 3 Jun 2026 12:07:17 -0400 +Subject: [PATCH 1/2] Use the same feature gates on `check` tests as `format` + +The test-pypi feature is used as a proxy for "this test does networking" so people running in offline scenarios don't run them. + +Fixes #19658 +--- + crates/uv/tests/it/main.rs | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/crates/uv/tests/it/main.rs b/crates/uv/tests/it/main.rs +index 30c27554ae985..cb1a3b6d660a7 100644 +--- a/crates/uv/tests/it/main.rs ++++ b/crates/uv/tests/it/main.rs +@@ -39,7 +39,7 @@ mod edit; + #[cfg(all(feature = "test-python", feature = "test-pypi"))] + mod export; + +-#[cfg(feature = "test-python")] ++#[cfg(all(feature = "test-python", feature = "test-pypi"))] + mod check; + + #[cfg(all(feature = "test-python", feature = "test-pypi"))] + +From b52907462863ccdafdde4a55fd8b050d87da32ad Mon Sep 17 00:00:00 2001 +From: Aria Desires +Date: Wed, 3 Jun 2026 13:10:53 -0400 +Subject: [PATCH 2/2] move both to r2 + +--- + crates/uv/tests/it/main.rs | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/crates/uv/tests/it/main.rs b/crates/uv/tests/it/main.rs +index cb1a3b6d660a7..27bf679237cac 100644 +--- a/crates/uv/tests/it/main.rs ++++ b/crates/uv/tests/it/main.rs +@@ -39,10 +39,10 @@ mod edit; + #[cfg(all(feature = "test-python", feature = "test-pypi"))] + mod export; + +-#[cfg(all(feature = "test-python", feature = "test-pypi"))] ++#[cfg(all(feature = "test-python", feature = "test-r2"))] + mod check; + +-#[cfg(all(feature = "test-python", feature = "test-pypi"))] ++#[cfg(all(feature = "test-python", feature = "test-r2"))] + mod format; + + mod help; diff --git a/uv.spec b/uv.spec index 30e9bb9..72dc7a6 100644 --- a/uv.spec +++ b/uv.spec @@ -154,6 +154,10 @@ Source1: uv.toml # https://github.com/astral-sh/uv/issues/4451 Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch +# fix feature-gates on format and check tests to specify they access r2 +# https://github.com/astral-sh/uv/pull/19661 +Patch: %{url}/pull/19661.patch + # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} @@ -639,16 +643,6 @@ skip="${skip-} --skip user_agent_version::test_user_agent_has_linehaul" skip="${skip-} --skip user_agent_version::test_user_agent_has_subcommand" skip="${skip-} --skip user_agent_version::test_user_agent_has_version" -# Some tests for “uv check” introduced in 0.11.18 require network access -# https://github.com/astral-sh/uv/issues/19658 -skip="${skip-} --skip check::check_missing_pyproject_toml" -skip="${skip-} --skip check::check_no_project" -skip="${skip-} --skip check::check_project" -skip="${skip-} --skip check::check_ty_version_no_match" -skip="${skip-} --skip check::check_ty_version_pinned_verbose" -skip="${skip-} --skip check::check_type_error" -skip="${skip-} --skip check::check_with_undeclared_dependency" - %cargo_test -- -- --exact ${skip-} %endif From 5e8acb4addf34c36fa65a4531a950e56a444cafa Mon Sep 17 00:00:00 2001 From: Python Maint Date: Thu, 4 Jun 2026 01:36:21 +0200 Subject: [PATCH 31/79] Rebuilt for Python 3.15 From 4b753d0addf145f5698f4269976798b6ebd9c9eb Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 4 Jun 2026 07:07:47 +0100 Subject: [PATCH 32/79] Update to 0.11.19 (close RHBZ#2484591) --- .gitignore | 1 + 19661.patch | 52 ---------------------------------------------------- sources | 2 +- uv.spec | 6 +----- 4 files changed, 3 insertions(+), 58 deletions(-) delete mode 100644 19661.patch diff --git a/.gitignore b/.gitignore index 2bba8e8..bb6bca6 100644 --- a/.gitignore +++ b/.gitignore @@ -213,3 +213,4 @@ /uv-0.11.15.tar.gz /uv-0.11.16.tar.gz /uv-0.11.18.tar.gz +/uv-0.11.19.tar.gz diff --git a/19661.patch b/19661.patch deleted file mode 100644 index 72c1f1e..0000000 --- a/19661.patch +++ /dev/null @@ -1,52 +0,0 @@ -From e1abeab3147489e3d1d7385d6973cabd33d81ff6 Mon Sep 17 00:00:00 2001 -From: Aria Desires -Date: Wed, 3 Jun 2026 12:07:17 -0400 -Subject: [PATCH 1/2] Use the same feature gates on `check` tests as `format` - -The test-pypi feature is used as a proxy for "this test does networking" so people running in offline scenarios don't run them. - -Fixes #19658 ---- - crates/uv/tests/it/main.rs | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/crates/uv/tests/it/main.rs b/crates/uv/tests/it/main.rs -index 30c27554ae985..cb1a3b6d660a7 100644 ---- a/crates/uv/tests/it/main.rs -+++ b/crates/uv/tests/it/main.rs -@@ -39,7 +39,7 @@ mod edit; - #[cfg(all(feature = "test-python", feature = "test-pypi"))] - mod export; - --#[cfg(feature = "test-python")] -+#[cfg(all(feature = "test-python", feature = "test-pypi"))] - mod check; - - #[cfg(all(feature = "test-python", feature = "test-pypi"))] - -From b52907462863ccdafdde4a55fd8b050d87da32ad Mon Sep 17 00:00:00 2001 -From: Aria Desires -Date: Wed, 3 Jun 2026 13:10:53 -0400 -Subject: [PATCH 2/2] move both to r2 - ---- - crates/uv/tests/it/main.rs | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/crates/uv/tests/it/main.rs b/crates/uv/tests/it/main.rs -index cb1a3b6d660a7..27bf679237cac 100644 ---- a/crates/uv/tests/it/main.rs -+++ b/crates/uv/tests/it/main.rs -@@ -39,10 +39,10 @@ mod edit; - #[cfg(all(feature = "test-python", feature = "test-pypi"))] - mod export; - --#[cfg(all(feature = "test-python", feature = "test-pypi"))] -+#[cfg(all(feature = "test-python", feature = "test-r2"))] - mod check; - --#[cfg(all(feature = "test-python", feature = "test-pypi"))] -+#[cfg(all(feature = "test-python", feature = "test-r2"))] - mod format; - - mod help; diff --git a/sources b/sources index 4415a51..66e8032 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.18.tar.gz) = 59ef43479bee5cc36dc5966ef5ec7bacb22e17d831ee2a0f8246d73c432cd0da76d230882afc08b31b610f92c333547285af420597f3f696a8acc30107cb2141 +SHA512 (uv-0.11.19.tar.gz) = 053c0372ded66ec8bcb109524ac67cc035722573ab4ac1a05ffcde6a126f4b67515901e45978b535e3051976effbdf89b99ebb59b62174389e3097ad058eda04 diff --git a/uv.spec b/uv.spec index 72dc7a6..3ab4d69 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.18 +Version: 0.11.19 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -154,10 +154,6 @@ Source1: uv.toml # https://github.com/astral-sh/uv/issues/4451 Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch -# fix feature-gates on format and check tests to specify they access r2 -# https://github.com/astral-sh/uv/pull/19661 -Patch: %{url}/pull/19661.patch - # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} From b0def776a46e712cd47ad1101e4cf8e23dd3f937 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 4 Jun 2026 11:55:05 +0100 Subject: [PATCH 33/79] Allow tikv-jemallocator 0.7 --- uv.spec | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/uv.spec b/uv.spec index 3ab4d69..2113050 100644 --- a/uv.spec +++ b/uv.spec @@ -495,6 +495,17 @@ tomcli set crates/uv/Cargo.toml del dependencies.tracing-durations-export # # https://bugzilla.redhat.com/show_bug.cgi?id=1234567 # tomcli set Cargo.toml str workspace.dependencies.foocrate.version 0.1.2 +# tikv-jemallocator +# wanted: 0.6.0 +# currently packaged: 0.7.0 +# We haven’t suggested this upstream because we know they use renovate with +# dependency cooldowns, and we expect they will soon update without prompting. +# We use sed instead of tomcli because the target.cfg(…) expression is a +# *mess*, and we don’t want to have to write it out here. +sed --regexp-extended --in-place \ + 's/^(tikv-jemallocator\b.*version = ")0\.6\.0"/\1>=0.6.0, <0.8.0"/' \ + crates/uv-performance-memory-allocator/Cargo.toml + %cargo_prep From 2a55ef3b100a5d41171816678d512cfdbc78343b Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sun, 7 Jun 2026 08:40:16 +0100 Subject: [PATCH 34/79] =?UTF-8?q?Further=20decrease=20max.=20parallelism?= =?UTF-8?q?=20to=20avoid=20=E2=80=9Ctoo=20many=20open=20files=E2=80=9D?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit [skip changelog] --- uv.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/uv.spec b/uv.spec index 2113050..58e5715 100644 --- a/uv.spec +++ b/uv.spec @@ -178,7 +178,7 @@ ExcludeArch: %{ix86} # Compilation may fail on builders with very many cores (e.g. 192 cores) due to # “too many open files.” Try to keep the files/core ratio from getting too low. -%global _smp_ncpus_max 72 +%global _smp_ncpus_max 48 BuildRequires: cargo-rpm-macros >= 24 BuildRequires: rust2rpm-helper From dee525ae66fc16108fc3e787fa7a2cb204bb9642 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Fri, 12 Jun 2026 13:02:29 +0100 Subject: [PATCH 35/79] Update to 0.11.21 (close RHBZ#2487856) --- .gitignore | 1 + 19819.patch | 69 +++++++++++++++++++++++++++++++++++++++++++++++++++++ sources | 2 +- uv.spec | 11 ++++++++- 4 files changed, 81 insertions(+), 2 deletions(-) create mode 100644 19819.patch diff --git a/.gitignore b/.gitignore index bb6bca6..98c0bbb 100644 --- a/.gitignore +++ b/.gitignore @@ -214,3 +214,4 @@ /uv-0.11.16.tar.gz /uv-0.11.18.tar.gz /uv-0.11.19.tar.gz +/uv-0.11.21.tar.gz diff --git a/19819.patch b/19819.patch new file mode 100644 index 0000000..50b33ea --- /dev/null +++ b/19819.patch @@ -0,0 +1,69 @@ +From d89c45d63819dc2df03956ba9291a1dcb7ee574f Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Fri, 12 Jun 2026 14:50:33 +0100 +Subject: [PATCH] Conditionalize a few new tests on the test-pypi feature + +--- + crates/uv/tests/it/upgrade.rs | 7 +++++++ + 1 file changed, 7 insertions(+) + +diff --git a/crates/uv/tests/it/upgrade.rs b/crates/uv/tests/it/upgrade.rs +index e92ef2fcbecee..2cb3e74c560cb 100644 +--- a/crates/uv/tests/it/upgrade.rs ++++ b/crates/uv/tests/it/upgrade.rs +@@ -114,6 +114,7 @@ fn upgrade_help() { + } + + #[test] ++#[cfg(feature = "test-pypi")] + fn upgrade_selects_normalized_production_dependency() -> Result<()> { + let context = uv_test::test_context!("3.12"); + let pyproject_toml = r#" +@@ -344,6 +345,7 @@ fn upgrade_expands_compatible_constraint_for_multiple_fork_versions() -> Result< + } + + #[test] ++#[cfg(feature = "test-pypi")] + fn upgrade_updates_requirement_without_updating_lockfile_or_environment() -> Result<()> { + let context = uv_test::test_context!("3.12"); + let initial_pyproject_toml = r#" +@@ -417,6 +419,7 @@ fn upgrade_updates_requirement_without_updating_lockfile_or_environment() -> Res + } + + #[test] ++#[cfg(feature = "test-pypi")] + fn upgrade_reports_no_solution_without_mutation() -> Result<()> { + let context = uv_test::test_context!("3.12"); + let pyproject_toml = r#" +@@ -450,6 +453,7 @@ fn upgrade_reports_no_solution_without_mutation() -> Result<()> { + } + + #[test] ++#[cfg(feature = "test-pypi")] + fn upgrade_reports_no_version_change_without_mutation() -> Result<()> { + let context = uv_test::test_context!("3.12"); + let pyproject_toml = r#" +@@ -784,6 +788,7 @@ fn upgrade_rejects_non_registry_source_for_top_level_extra() -> Result<()> { + } + + #[test] ++#[cfg(feature = "test-pypi")] + fn upgrade_allows_registry_source() -> Result<()> { + let context = uv_test::test_context!("3.12"); + let empty_index = context.temp_dir.child("empty-index"); +@@ -847,6 +852,7 @@ fn upgrade_allows_registry_source() -> Result<()> { + } + + #[test] ++#[cfg(feature = "test-pypi")] + fn upgrade_ignores_inapplicable_non_registry_source() -> Result<()> { + let context = uv_test::test_context!("3.12"); + let pyproject_toml = r#" +@@ -953,6 +959,7 @@ fn upgrade_rejects_workspace_root_non_registry_source() -> Result<()> { + } + + #[test] ++#[cfg(feature = "test-pypi")] + fn upgrade_updates_nested_workspace_member_only() -> Result<()> { + let context = uv_test::test_context!("3.12"); + let workspace_pyproject_toml = r#" diff --git a/sources b/sources index 66e8032..9491c91 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.19.tar.gz) = 053c0372ded66ec8bcb109524ac67cc035722573ab4ac1a05ffcde6a126f4b67515901e45978b535e3051976effbdf89b99ebb59b62174389e3097ad058eda04 +SHA512 (uv-0.11.21.tar.gz) = c1057ff5e2387dc190d12c71fbdfddca3d99e03d2b00065f0077f9c912dbcb19ba8b81cbcd874c31f613a5ab2fafef77f6034589ccab5ee33940a6eb72714598 diff --git a/uv.spec b/uv.spec index 58e5715..6718763 100644 --- a/uv.spec +++ b/uv.spec @@ -11,7 +11,7 @@ %bcond it %{undefined el10} Name: uv -Version: 0.11.19 +Version: 0.11.21 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -154,6 +154,10 @@ Source1: uv.toml # https://github.com/astral-sh/uv/issues/4451 Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch +# Conditionalize a few new tests on the test-pypi feature +# https://github.com/astral-sh/uv/pull/19819 +Patch: %{url}/pull/19819.patch + # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} @@ -634,6 +638,11 @@ skip="${skip-} --skip tests::built_by_uv_building" # dependency version differing from Cargo.lock. skip="${skip-} --skip base_client::tests::retried_status_codes" +# Harmless and trivial discrepancy in an error message: +# 8 │- Caused by: error decoding response body for url (http://[LOCALHOST]/tqdm/) +# 8 │+ Caused by: error decoding response body +skip="${skip-} --skip network::retry_read_timeout_index" + # These fail flakily: most frequently on ppc64le, but this seems to be just a # matter of luck, since we suspect a race condition. We have also seen failures # on aarch64. This is probably a race involving the SSL_CERT_FILE environment From cf8329a48c21ac349dd6a53514642a229c998f9f Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 17 Jun 2026 12:15:57 +0100 Subject: [PATCH 36/79] Rebuilt with webpki-root-certs 1.0.8 From 44ed0d1deffebc21d202f6727535408ec245b476 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 17 Jun 2026 20:30:42 +0100 Subject: [PATCH 37/79] Fix skipping tests that require alternative versions of Python Some of these were moved around upstream. --- uv.spec | 69 +++++++++++++++++++++++++++++++++------------------------ 1 file changed, 40 insertions(+), 29 deletions(-) diff --git a/uv.spec b/uv.spec index 6718763..a2f122e 100644 --- a/uv.spec +++ b/uv.spec @@ -1,14 +1,8 @@ %bcond check 1 -# Should we run integration tests, many of which require specific Python -# interpreter versions (major.minor, not major.minor.patch)? This adds a few -# dozen tests, but adds BuildRequires on more Pythons, and could reduce our -# confidence that everything works correctly in an environment that only has -# the main system Python. -# -# EPEL10 does not have alternative versions of Python, so we cannot run most of -# the integration tests there, and manually selecting those we can run would be -# far too tedious. -%bcond it %{undefined el10} +# Should we run tests that require specific Python interpreter versions +# (major.minor, not major.minor.patch)? This adds a few dozen tests, but adds +# BuildRequires on more Python interpreters (which aren’t available in EPEL). +%bcond other_python_versions %{undefined el10} Name: uv Version: 0.11.21 @@ -187,7 +181,7 @@ ExcludeArch: %{ix86} BuildRequires: cargo-rpm-macros >= 24 BuildRequires: rust2rpm-helper BuildRequires: tomcli -%if %{with check} && %{with it} +%if %{with check} && %{with other_python_versions} # See trove classifiers in pyproject.toml for supported Pythons. BuildRequires: /usr/bin/python3.9 BuildRequires: /usr/bin/python3.10 @@ -461,24 +455,41 @@ tomcli set crates/uv/Cargo.toml lists delitem features.test-defaults \ tomcli set crates/uv-audit/Cargo.toml lists delitem features.default \ 'test-(osv)' -%if %{without it} -# Integration tests (it crate) nearly all require specific Python interpreter -# versions (major.minor, not major.minor.patch, unless the python-patch feature -# is enabled). We might choose to disable this in order to double-check that -# everything else works well with only the primary system Python in the -# environment. +%if %{without other_python_versions} +# Many of these tests require specific Python versions (major.minor, not +# major.minor.patch, unless the python-patch feature is enabled). Manually +# selecting the tests in these modules that would succeed with just the system +# Python would be far too tedious. +omit_modules() { + set -o nounset + set -o errexit + main_module="${1}" + commented_modules='' + comment='Downstream-only: skip, needs specific Python interpreter versions' + shift + while [ "${#}" != 0 ] + do + commented_modules="${commented_modules-}${commented_modules+|}${1}" + shift + done + sed --regexp-extended --in-place \ + "s@mod (${commented_modules});@// ${comment}\n#[cfg(any())]\n&@" \ + "${main_module}" +} +# -p uv --test build +omit_modules crates/uv/tests/build/main.rs build_backend # -p uv --test it: -mods="${mods-}${mods+|}branching_urls" -mods="${mods-}${mods+|}build_backend" -mods="${mods-}${mods+|}pip_(check|list|show|tree|uninstall)" -mods="${mods-}${mods+|}python_(dir|find|install|list|pin)" -mods="${mods-}${mods+|}venv" -mods="${mods-}${mods+|}version" -mods="${mods-}${mods+|}workspace" -comment='Downstream-only: skip, needs specific Python interpreter versions' -sed --regexp-extended --in-place \ - "s@mod (${mods});@// ${comment}\n#[cfg(any())]\n&@" \ - crates/uv/tests/it/main.rs +omit_modules crates/uv/tests/it/main.rs \ + auth branching_urls network upgrade version +# -p uv --test python: +omit_modules crates/uv/tests/python/main.rs \ + 'python_(dir|find|install|list|pin)' venv +# -p uv --test workspace: +omit_modules crates/uv/tests/workspace/main.rs \ + workspace 'workspace_(dir|list|metadata)' +# -p uv --test pip: +omit_modules crates/uv/tests/pip/main.rs \ + 'pip_(debug|list|show|tree|uninstall)' %endif # For unclear reasons, maturin checks for the presence of optional crate @@ -580,7 +591,7 @@ skip="${skip-} --skip keyring::tests::fetch_url_with_empty_username" skip="${skip-} --skip keyring::tests::fetch_url_with_no_username" skip="${skip-} --skip keyring::tests::fetch_url_with_password" -%if %{without it} +%if %{without other_python_versions} # These tests require specific Python interpreter versions, which upstream # normally downloads, precompiled, into the build area. skip="${skip-} --skip version::self_version" From d405e63ad8c19f6223193d32303de9b4beef92c1 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 18 Jun 2026 20:28:48 +0100 Subject: [PATCH 38/79] Rebuilt with `reflink-copy` 0.1.30 From 2ed0f74a9052bbe90f71c677f02ea9fb31a2e76c Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 18 Jun 2026 20:28:48 +0100 Subject: [PATCH 39/79] Rebuilt with `reflink-copy` 0.1.30 From 4b679487806d5c5433d92fd72651e7be07f2dc89 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Fri, 19 Jun 2026 06:22:44 +0100 Subject: [PATCH 40/79] Update to 0.11.22 --- .gitignore | 1 + 19819.patch | 69 ----------------------------------------------------- sources | 2 +- uv.spec | 6 +---- 4 files changed, 3 insertions(+), 75 deletions(-) delete mode 100644 19819.patch diff --git a/.gitignore b/.gitignore index 98c0bbb..a7e932f 100644 --- a/.gitignore +++ b/.gitignore @@ -215,3 +215,4 @@ /uv-0.11.18.tar.gz /uv-0.11.19.tar.gz /uv-0.11.21.tar.gz +/uv-0.11.22.tar.gz diff --git a/19819.patch b/19819.patch deleted file mode 100644 index 50b33ea..0000000 --- a/19819.patch +++ /dev/null @@ -1,69 +0,0 @@ -From d89c45d63819dc2df03956ba9291a1dcb7ee574f Mon Sep 17 00:00:00 2001 -From: "Benjamin A. Beasley" -Date: Fri, 12 Jun 2026 14:50:33 +0100 -Subject: [PATCH] Conditionalize a few new tests on the test-pypi feature - ---- - crates/uv/tests/it/upgrade.rs | 7 +++++++ - 1 file changed, 7 insertions(+) - -diff --git a/crates/uv/tests/it/upgrade.rs b/crates/uv/tests/it/upgrade.rs -index e92ef2fcbecee..2cb3e74c560cb 100644 ---- a/crates/uv/tests/it/upgrade.rs -+++ b/crates/uv/tests/it/upgrade.rs -@@ -114,6 +114,7 @@ fn upgrade_help() { - } - - #[test] -+#[cfg(feature = "test-pypi")] - fn upgrade_selects_normalized_production_dependency() -> Result<()> { - let context = uv_test::test_context!("3.12"); - let pyproject_toml = r#" -@@ -344,6 +345,7 @@ fn upgrade_expands_compatible_constraint_for_multiple_fork_versions() -> Result< - } - - #[test] -+#[cfg(feature = "test-pypi")] - fn upgrade_updates_requirement_without_updating_lockfile_or_environment() -> Result<()> { - let context = uv_test::test_context!("3.12"); - let initial_pyproject_toml = r#" -@@ -417,6 +419,7 @@ fn upgrade_updates_requirement_without_updating_lockfile_or_environment() -> Res - } - - #[test] -+#[cfg(feature = "test-pypi")] - fn upgrade_reports_no_solution_without_mutation() -> Result<()> { - let context = uv_test::test_context!("3.12"); - let pyproject_toml = r#" -@@ -450,6 +453,7 @@ fn upgrade_reports_no_solution_without_mutation() -> Result<()> { - } - - #[test] -+#[cfg(feature = "test-pypi")] - fn upgrade_reports_no_version_change_without_mutation() -> Result<()> { - let context = uv_test::test_context!("3.12"); - let pyproject_toml = r#" -@@ -784,6 +788,7 @@ fn upgrade_rejects_non_registry_source_for_top_level_extra() -> Result<()> { - } - - #[test] -+#[cfg(feature = "test-pypi")] - fn upgrade_allows_registry_source() -> Result<()> { - let context = uv_test::test_context!("3.12"); - let empty_index = context.temp_dir.child("empty-index"); -@@ -847,6 +852,7 @@ fn upgrade_allows_registry_source() -> Result<()> { - } - - #[test] -+#[cfg(feature = "test-pypi")] - fn upgrade_ignores_inapplicable_non_registry_source() -> Result<()> { - let context = uv_test::test_context!("3.12"); - let pyproject_toml = r#" -@@ -953,6 +959,7 @@ fn upgrade_rejects_workspace_root_non_registry_source() -> Result<()> { - } - - #[test] -+#[cfg(feature = "test-pypi")] - fn upgrade_updates_nested_workspace_member_only() -> Result<()> { - let context = uv_test::test_context!("3.12"); - let workspace_pyproject_toml = r#" diff --git a/sources b/sources index 9491c91..5776fd1 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.21.tar.gz) = c1057ff5e2387dc190d12c71fbdfddca3d99e03d2b00065f0077f9c912dbcb19ba8b81cbcd874c31f613a5ab2fafef77f6034589ccab5ee33940a6eb72714598 +SHA512 (uv-0.11.22.tar.gz) = 5c2ea2478721af3b34152809eff7a37ea19eb8ea88c912a0a75b4a112c3c56b16e798226a5c84d906633d71ee4a38d9f8fa187adc17a09c6430edcae0272c0df diff --git a/uv.spec b/uv.spec index a2f122e..06e3253 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined el10} Name: uv -Version: 0.11.21 +Version: 0.11.22 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -148,10 +148,6 @@ Source1: uv.toml # https://github.com/astral-sh/uv/issues/4451 Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch -# Conditionalize a few new tests on the test-pypi feature -# https://github.com/astral-sh/uv/pull/19819 -Patch: %{url}/pull/19819.patch - # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} From 24393cd6e2d63bc7c0319a4f5a7b47e9fbf7bcc2 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sun, 21 Jun 2026 11:49:49 +0100 Subject: [PATCH 41/79] Update to 0.11.23 (close RHBZ#2490666) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index a7e932f..15b0e92 100644 --- a/.gitignore +++ b/.gitignore @@ -216,3 +216,4 @@ /uv-0.11.19.tar.gz /uv-0.11.21.tar.gz /uv-0.11.22.tar.gz +/uv-0.11.23.tar.gz diff --git a/sources b/sources index 5776fd1..f6bf735 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.22.tar.gz) = 5c2ea2478721af3b34152809eff7a37ea19eb8ea88c912a0a75b4a112c3c56b16e798226a5c84d906633d71ee4a38d9f8fa187adc17a09c6430edcae0272c0df +SHA512 (uv-0.11.23.tar.gz) = 4d40479ca540294fbdb346ca8c2dcb91fef572d1e663951ffea2370f9d09f12140aed2029be1178332874ac80150155b88774798c6424686badf7eeef646ce3f diff --git a/uv.spec b/uv.spec index 06e3253..bee49aa 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined el10} Name: uv -Version: 0.11.22 +Version: 0.11.23 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From 58eb0c31633d9c506d66589d4c9047ad0f090c4b Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 24 Jun 2026 11:15:22 +0100 Subject: [PATCH 42/79] Update to 0.11.24 (close RHBZ#2492025) --- .gitignore | 1 + sources | 2 +- uv.spec | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index 15b0e92..cbdf68f 100644 --- a/.gitignore +++ b/.gitignore @@ -217,3 +217,4 @@ /uv-0.11.21.tar.gz /uv-0.11.22.tar.gz /uv-0.11.23.tar.gz +/uv-0.11.24.tar.gz diff --git a/sources b/sources index f6bf735..4018252 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.23.tar.gz) = 4d40479ca540294fbdb346ca8c2dcb91fef572d1e663951ffea2370f9d09f12140aed2029be1178332874ac80150155b88774798c6424686badf7eeef646ce3f +SHA512 (uv-0.11.24.tar.gz) = 4927f0280b4041293180db6efed8c31facbb23cb4349a2383ef0488c26b21a3fc6ab98f94e7ff41bf4411f65d158208345632e130a6fae9f2bc85d40deddefec diff --git a/uv.spec b/uv.spec index bee49aa..4924912 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined el10} Name: uv -Version: 0.11.23 +Version: 0.11.24 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From a0ce58a6c99b418049b021db2c9e0eab1110802f Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sat, 27 Jun 2026 06:26:41 +0100 Subject: [PATCH 43/79] Update to 0.11.25 --- .gitignore | 1 + sources | 2 +- uv.spec | 3 ++- 3 files changed, 4 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index cbdf68f..235ed96 100644 --- a/.gitignore +++ b/.gitignore @@ -218,3 +218,4 @@ /uv-0.11.22.tar.gz /uv-0.11.23.tar.gz /uv-0.11.24.tar.gz +/uv-0.11.25.tar.gz diff --git a/sources b/sources index 4018252..82e9d50 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.24.tar.gz) = 4927f0280b4041293180db6efed8c31facbb23cb4349a2383ef0488c26b21a3fc6ab98f94e7ff41bf4411f65d158208345632e130a6fae9f2bc85d40deddefec +SHA512 (uv-0.11.25.tar.gz) = 9b993ae026d55ee8dfe13101e0fdbe026d81b77ff42b20ad42ff72c9708f2d767cde94010e69cd4f65fa8821c43958bc665893761119770deba70823d895298c diff --git a/uv.spec b/uv.spec index 4924912..bceac92 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined el10} Name: uv -Version: 0.11.24 +Version: 0.11.25 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -97,6 +97,7 @@ Summary: An extremely fast Python package installer and resolver, written # ISC # LGPL-3.0-or-later OR MPL-2.0 # MIT +# MIT AND (MIT OR Apache-2.0) # MIT OR Apache-2.0 # MIT OR LGPL-3.0-or-later # MIT OR Zlib OR Apache-2.0 From 7e46b8e3f9bc1214461041ccbbd23f06b0afebb1 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 2 Jul 2026 06:04:00 +0100 Subject: [PATCH 44/79] Update to 0.11.26 (close RHBZ#2495097) --- .gitignore | 1 + sources | 2 +- uv.spec | 5 ++--- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.gitignore b/.gitignore index 235ed96..2c78ba6 100644 --- a/.gitignore +++ b/.gitignore @@ -219,3 +219,4 @@ /uv-0.11.23.tar.gz /uv-0.11.24.tar.gz /uv-0.11.25.tar.gz +/uv-0.11.26.tar.gz diff --git a/sources b/sources index 82e9d50..f0835cd 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.25.tar.gz) = 9b993ae026d55ee8dfe13101e0fdbe026d81b77ff42b20ad42ff72c9708f2d767cde94010e69cd4f65fa8821c43958bc665893761119770deba70823d895298c +SHA512 (uv-0.11.26.tar.gz) = 8be3842d1a534765a99a130a857c860a2b6ec2dd517cbdff7f697db55500d1092b4f323459625d433635f3559a058eef98140eb65b1082394994d72c5d329ee1 diff --git a/uv.spec b/uv.spec index bceac92..6fd3ea5 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined el10} Name: uv -Version: 0.11.25 +Version: 0.11.26 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -510,8 +510,7 @@ tomcli set crates/uv/Cargo.toml del dependencies.tracing-durations-export # tikv-jemallocator # wanted: 0.6.0 # currently packaged: 0.7.0 -# We haven’t suggested this upstream because we know they use renovate with -# dependency cooldowns, and we expect they will soon update without prompting. +# https://github.com/astral-sh/uv/pull/19735 # We use sed instead of tomcli because the target.cfg(…) expression is a # *mess*, and we don’t want to have to write it out here. sed --regexp-extended --in-place \ From c05ebc571f5b8b4fa413fb78e864e6018401b5b9 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 2 Jul 2026 14:38:42 +0100 Subject: [PATCH 45/79] Simplify .gitignore [skip changelog] --- .gitignore | 223 +---------------------------------------------------- 1 file changed, 1 insertion(+), 222 deletions(-) diff --git a/.gitignore b/.gitignore index 2c78ba6..36e4cb1 100644 --- a/.gitignore +++ b/.gitignore @@ -1,222 +1 @@ -/pubgrub-3f0ba760951ab0deeac874b98bb18fc90103fcf7.tar.gz -/reqwest-middleware-21ceec9a5fd2e8d6f71c3ea2999078fecbd13cbe.tar.gz -/rs-async-zip-011b24604fa7bc223daaad7712c0694bac8f0a87.tar.gz -/uv-0.2.32.tar.gz -/uv-0.2.33.tar.gz -/pubgrub-2fac39371a47e7cb821e510aaa4de25405413d29.tar.gz -/uv-0.2.34.tar.gz -/uv-0.2.35.tar.gz -/uv-0.2.37-filtered.tar.zst -/uv-0.3.0-filtered.tar.zst -/pubgrub-aaef464c1b0d8eea4ff9ffaee4f3458c236d10da.tar.gz -/reqwest-middleware-5e3eaf254b5bd481c75d2710eed055f95b756913.tar.gz -/uv-0.3.2-filtered.tar.zst -/uv-0.3.3-filtered.tar.zst -/pubgrub-388685a8711092971930986644cfed152d1a1f6c.tar.gz -/uv-0.3.4-filtered.tar.zst -/tl-6e25b2ee2513d75385101a8ff9f591ef51f314ec.tar.gz -/uv-0.3.5-filtered.tar.zst -/uv-0.4.0-filtered.tar.zst -/uv-0.4.1-filtered.tar.zst -/uv-0.4.2-filtered.tar.zst -/uv-0.4.4-filtered.tar.zst -/uv-0.4.5-filtered.tar.zst -/uv-0.4.6-filtered.tar.zst -/uv-0.4.7-filtered.tar.zst -/uv-0.4.8-filtered.tar.zst -/uv-0.4.9-filtered.tar.zst -/uv-0.4.10-filtered.tar.zst -/uv-0.4.15.tar.gz -/uv-0.4.16.tar.gz -/uv-0.4.17.tar.gz -/uv-0.4.18.tar.gz -/uv-0.4.19.tar.gz -/uv-0.4.20.tar.gz -/uv-0.4.21.tar.gz -/uv-0.4.22.tar.gz -/uv-0.4.23.tar.gz -/pubgrub-19c77268c0ad5f69d7e12126e0cfacfbba466481.tar.gz -/uv-0.4.24.tar.gz -/uv-0.4.25.tar.gz -/pubgrub-7243f4faf8e54837aa8a401a18406e7173de4ad5.tar.gz -/reqwest-middleware-d95ec5a99fcc9a4339e1850d40378bbfe55ab121.tar.gz -/uv-0.4.26.tar.gz -/uv-0.4.27.tar.gz -/uv-0.4.28.tar.gz -/uv-0.4.29.tar.gz -/pubgrub-95e1390399cdddee986b658be19587eb1fdb2d79.tar.gz -/uv-0.4.30.tar.gz -/uv-0.5.0.tar.gz -/uv-0.5.1.tar.gz -/uv-0.5.2.tar.gz -/rs-async-zip-c909fda63fcafe4af496a07bfda28a5aae97e58d.tar.gz -/uv-0.5.3.tar.gz -/pubgrub-57afc831bf2551f164617a10383cf288bf5d190d.tar.gz -/uv-0.5.4.tar.gz -/uv-0.5.5.tar.gz -/pubgrub-9cd9049a64c7352de2ff3b525b9ae36421b0cc18.tar.gz -/uv-0.5.6.tar.gz -/pubgrub-57832d0588fbb7aab824813481104761dc1c7740.tar.gz -/uv-0.5.7.tar.gz -/uv-0.5.8.tar.gz -/uv-0.5.9.tar.gz -/uv-0.5.10.tar.gz -/pubgrub-05e8d12cea8d72c6d2d017900e478d0abd28fef4.tar.gz -/uv-0.5.11.tar.gz -/uv-0.5.12.tar.gz -/pubgrub-648aa343486e5529953153781fc86025c73c4a61.tar.gz -/uv-0.5.13.tar.gz -/uv-0.5.14.tar.gz -/uv-0.5.15.tar.gz -/uv-0.5.16.tar.gz -/uv-0.5.17.tar.gz -/uv-0.5.18.tar.gz -/uv-0.5.19.tar.gz -/uv-0.5.20.tar.gz -/uv-0.5.21.tar.gz -/uv-0.5.22.tar.gz -/uv-0.5.23.tar.gz -/uv-0.5.24.tar.gz -/uv-0.5.25.tar.gz -/uv-0.5.26.tar.gz -/uv-0.5.27.tar.gz -/pubgrub-b70cf707aa43f21b32f3a61b8a0889b15032d5c4.tar.gz -/tokio-tar-ba2b140f27d081c463335f0d68b5f8df8e6c845e.tar.gz -/uv-0.5.28.tar.gz -/tokio-tar-efeaea927c7a40ee66121de2e1bebfd5d7a4a602.tar.gz -/uv-0.5.29.tar.gz -/uv-0.5.30.tar.gz -/uv-0.5.31.tar.gz -/uv-0.6.0.tar.gz -/uv-0.6.1.tar.gz -/uv-0.6.2.tar.gz -/uv-0.6.3.tar.gz -/uv-0.6.4.tar.gz -/uv-0.6.5.tar.gz -/uv-0.6.6.tar.gz -/uv-0.6.7.tar.gz -/uv-0.6.8.tar.gz -/uv-0.6.9.tar.gz -/uv-0.6.10.tar.gz -/uv-0.6.11.tar.gz -/uv-0.6.12.tar.gz -/uv-0.6.13.tar.gz -/uv-0.6.14.tar.gz -/uv-0.6.16.tar.gz -/uv-0.6.17.tar.gz -/pubgrub-a3b4db3abb1829ce889fb89fa6d157fef529ef7e.tar.gz -/uv-0.7.0.tar.gz -/uv-0.7.1.tar.gz -/uv-0.7.2.tar.gz -/uv-0.7.3.tar.gz -/uv-0.7.4.tar.gz -/pubgrub-73d6ecf5a4e4eb1c754b8c3255c4d31bdc266fdb.tar.gz -/uv-0.7.5.tar.gz -/uv-0.7.6.tar.gz -/uv-0.7.8.tar.gz -/pubgrub-06ec5a5f59ffaeb6cf5079c6cb184467da06c9db.tar.gz -/uv-0.7.9.tar.gz -/uv-0.7.10.tar.gz -/uv-0.7.11.tar.gz -/uv-0.7.12.tar.gz -/uv-0.7.13.tar.gz -/uv-0.7.14.tar.gz -/reqwest-middleware-ad8b9d332d1773fde8b4cd008486de5973e0a3f8.tar.gz -/uv-0.7.15.tar.gz -/uv-0.7.16.tar.gz -/uv-0.7.17.tar.gz -/uv-0.7.18.tar.gz -/uv-0.7.19.tar.gz -/uv-0.7.20.tar.gz -/uv-0.7.21.tar.gz -/uv-0.7.22.tar.gz -/uv-0.8.0.tar.gz -/uv-0.8.1.tar.gz -/uv-0.8.2.tar.gz -/uv-0.8.3.tar.gz -/uv-0.8.4.tar.gz -/uv-0.8.5.tar.gz -/uv-0.8.6.tar.gz -/rs-async-zip-285e48742b74ab109887d62e1ae79e7c15fd4878.tar.gz -/uv-0.8.7.tar.gz -/uv-0.8.8.tar.gz -/uv-0.8.9.tar.gz -/uv-0.8.10.tar.gz -/uv-0.8.11.tar.gz -/uv-0.8.12.tar.gz -/tokio-tar-f1488188f1d1b54a73eb0c42a8b8f4b9ee87d688.tar.gz -/uv-0.8.13.tar.gz -/uv-0.8.14.tar.gz -/uv-0.8.15.tar.gz -/reqwest-middleware-7650ed76215a962a96d94a79be71c27bffde7ab2.tar.gz -/uv-0.8.16.tar.gz -/uv-0.8.17.tar.gz -/uv-0.8.18.tar.gz -/uv-0.8.19.tar.gz -/uv-0.8.20.tar.gz -/pubgrub-d8efd77673c9a90792da9da31b6c0da7ea8a324b.tar.gz -/uv-0.8.21.tar.gz -/uv-0.8.22.tar.gz -/uv-0.8.23.tar.gz -/uv-0.8.24.tar.gz -/uv-0.9.0.tar.gz -/uv-0.9.1.tar.gz -/uv-0.9.2.tar.gz -/uv-0.9.3.tar.gz -/uv-0.9.4.tar.gz -/uv-0.9.5.tar.gz -/uv-0.9.6.tar.gz -/rs-async-zip-f6a41d32866003c868d03ed791a89c794f61b703.tar.gz -/uv-0.9.7.tar.gz -/uv-0.9.8.tar.gz -/uv-0.9.9.tar.gz -/uv-0.9.10.tar.gz -/uv-0.9.11.tar.gz -/uv-0.9.12.tar.gz -/uv-0.9.13.tar.gz -/uv-0.9.14.tar.gz -/uv-0.9.15.tar.gz -/uv-0.9.16.tar.gz -/uv-0.9.17.tar.gz -/uv-0.9.18.tar.gz -/uv-0.9.20.tar.gz -/uv-0.9.21.tar.gz -/uv-0.9.22.tar.gz -/uv-0.9.26.tar.gz -/uv-0.9.27.tar.gz -/uv-0.9.28.tar.gz -/uv-0.9.29.tar.gz -/uv-0.9.30.tar.gz -/uv-0.10.0.tar.gz -/uv-0.10.1.tar.gz -/uv-0.10.2.tar.gz -/uv-0.10.3.tar.gz -/uv-0.10.4.tar.gz -/uv-0.10.5.tar.gz -/uv-0.10.6.tar.gz -/uv-0.10.7.tar.gz -/uv-0.10.8.tar.gz -/uv-0.10.9.tar.gz -/uv-0.10.10.tar.gz -/uv-0.10.11.tar.gz -/uv-0.10.12.tar.gz -/uv-0.11.2.tar.gz -/uv-0.11.4.tar.gz -/uv-0.11.5.tar.gz -/uv-0.11.6.tar.gz -/uv-0.11.7.tar.gz -/uv-0.11.9.tar.gz -/uv-0.11.10.tar.gz -/uv-0.11.11.tar.gz -/uv-0.11.12.tar.gz -/uv-0.11.14.tar.gz -/uv-0.11.15.tar.gz -/uv-0.11.16.tar.gz -/uv-0.11.18.tar.gz -/uv-0.11.19.tar.gz -/uv-0.11.21.tar.gz -/uv-0.11.22.tar.gz -/uv-0.11.23.tar.gz -/uv-0.11.24.tar.gz -/uv-0.11.25.tar.gz -/uv-0.11.26.tar.gz +/uv-*.tar.gz From e0cb68f3e2b690019a3478ff8fb893fe8a7d184c Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Tue, 7 Jul 2026 06:50:03 +0100 Subject: [PATCH 46/79] Update to 0.11.27 (close RHBZ#2497560) --- 20174.patch | 170 ++++++++++++++++++++++++++++++++++++++++++++++++++++ sources | 2 +- uv.spec | 14 ++++- 3 files changed, 183 insertions(+), 3 deletions(-) create mode 100644 20174.patch diff --git a/20174.patch b/20174.patch new file mode 100644 index 0000000..2ae827b --- /dev/null +++ b/20174.patch @@ -0,0 +1,170 @@ +From c77c2abf16c13b3ef26fae52b6bec97a7abad65b Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Tue, 7 Jul 2026 06:57:19 +0100 +Subject: [PATCH 1/4] Add BSD-3-Clause LICENSE file to ecosystem/jupyterlab + +https://github.com/jupyterlab/jupyterlab/raw/refs/tags/v4.6.1/LICENSE +--- + test/ecosystem/jupyterlab/LICENSE | 27 +++++++++++++++++++++++++++ + 1 file changed, 27 insertions(+) + create mode 100644 test/ecosystem/jupyterlab/LICENSE + +diff --git a/test/ecosystem/jupyterlab/LICENSE b/test/ecosystem/jupyterlab/LICENSE +new file mode 100644 +index 0000000000000..c73604f78a1f6 +--- /dev/null ++++ b/test/ecosystem/jupyterlab/LICENSE +@@ -0,0 +1,27 @@ ++Copyright (c) 2015-2025 Project Jupyter Contributors ++All rights reserved. ++ ++Redistribution and use in source and binary forms, with or without ++modification, are permitted provided that the following conditions are met: ++ ++1. Redistributions of source code must retain the above copyright notice, this ++ list of conditions and the following disclaimer. ++ ++2. Redistributions in binary form must reproduce the above copyright notice, ++ this list of conditions and the following disclaimer in the documentation ++ and/or other materials provided with the distribution. ++ ++3. Neither the name of the copyright holder nor the names of its ++ contributors may be used to endorse or promote products derived from ++ this software without specific prior written permission. ++ ++THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" ++AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE ++IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE ++DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE ++FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL ++DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER ++CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, ++OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE ++OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +From 0561c227905e972b0d415b0170053ce6ec278184 Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Tue, 7 Jul 2026 06:58:21 +0100 +Subject: [PATCH 2/4] Add BSD-3-Clause LICENSE file to ecosystem/pandas + +https://github.com/pandas-dev/pandas/raw/refs/tags/v3.0.4/LICENSE +--- + test/ecosystem/pandas/LICENSE | 31 +++++++++++++++++++++++++++++++ + 1 file changed, 31 insertions(+) + create mode 100644 test/ecosystem/pandas/LICENSE + +diff --git a/test/ecosystem/pandas/LICENSE b/test/ecosystem/pandas/LICENSE +new file mode 100644 +index 0000000000000..bd1cc2a30c626 +--- /dev/null ++++ b/test/ecosystem/pandas/LICENSE +@@ -0,0 +1,31 @@ ++BSD 3-Clause License ++ ++Copyright (c) 2008-2011, AQR Capital Management, LLC, Lambda Foundry, Inc. and PyData Development Team ++All rights reserved. ++ ++Copyright (c) 2011-2026, Open source contributors. ++ ++Redistribution and use in source and binary forms, with or without ++modification, are permitted provided that the following conditions are met: ++ ++* Redistributions of source code must retain the above copyright notice, this ++ list of conditions and the following disclaimer. ++ ++* Redistributions in binary form must reproduce the above copyright notice, ++ this list of conditions and the following disclaimer in the documentation ++ and/or other materials provided with the distribution. ++ ++* Neither the name of the copyright holder nor the names of its ++ contributors may be used to endorse or promote products derived from ++ this software without specific prior written permission. ++ ++THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" ++AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE ++IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE ++DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE ++FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL ++DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR ++SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER ++CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, ++OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE ++OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +From d21662e1800682b4058dac8bb39079620eb21400 Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Tue, 7 Jul 2026 06:59:25 +0100 +Subject: [PATCH 3/4] Add MIT LICENSE file to ecosystem/poetry + +https://github.com/python-poetry/poetry/raw/refs/tags/2.4.1/LICENSE +--- + test/ecosystem/poetry/LICENSE | 20 ++++++++++++++++++++ + 1 file changed, 20 insertions(+) + create mode 100644 test/ecosystem/poetry/LICENSE + +diff --git a/test/ecosystem/poetry/LICENSE b/test/ecosystem/poetry/LICENSE +new file mode 100644 +index 0000000000000..81a8e1e473986 +--- /dev/null ++++ b/test/ecosystem/poetry/LICENSE +@@ -0,0 +1,20 @@ ++Copyright (c) 2018-present Sébastien Eustace ++ ++Permission is hereby granted, free of charge, to any person obtaining ++a copy of this software and associated documentation files (the ++"Software"), to deal in the Software without restriction, including ++without limitation the rights to use, copy, modify, merge, publish, ++distribute, sublicense, and/or sell copies of the Software, and to ++permit persons to whom the Software is furnished to do so, subject to ++the following conditions: ++ ++The above copyright notice and this permission notice shall be ++included in all copies or substantial portions of the Software. ++ ++THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, ++EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF ++MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND ++NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE ++LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION ++OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION ++WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. + +From 708d1e5dfaaaee539308d60dbbfc0faa186885fd Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Tue, 7 Jul 2026 07:06:54 +0100 +Subject: [PATCH 4/4] Add MIT LICENSE file to ecosystem/semantic-kernel + +https://github.com/microsoft/semantic-kernel/raw/refs/tags/python-1.43.1/python/LICENSE +--- + test/ecosystem/semantic-kernel/LICENSE | 21 +++++++++++++++++++++ + 1 file changed, 21 insertions(+) + create mode 100644 test/ecosystem/semantic-kernel/LICENSE + +diff --git a/test/ecosystem/semantic-kernel/LICENSE b/test/ecosystem/semantic-kernel/LICENSE +new file mode 100644 +index 0000000000000..9e841e7a26e4e +--- /dev/null ++++ b/test/ecosystem/semantic-kernel/LICENSE +@@ -0,0 +1,21 @@ ++ MIT License ++ ++ Copyright (c) Microsoft Corporation. ++ ++ Permission is hereby granted, free of charge, to any person obtaining a copy ++ of this software and associated documentation files (the "Software"), to deal ++ in the Software without restriction, including without limitation the rights ++ to use, copy, modify, merge, publish, distribute, sublicense, and/or sell ++ copies of the Software, and to permit persons to whom the Software is ++ furnished to do so, subject to the following conditions: ++ ++ The above copyright notice and this permission notice shall be included in all ++ copies or substantial portions of the Software. ++ ++ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR ++ IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, ++ FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE ++ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER ++ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, ++ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE ++ SOFTWARE diff --git a/sources b/sources index f0835cd..19d1ff0 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.26.tar.gz) = 8be3842d1a534765a99a130a857c860a2b6ec2dd517cbdff7f697db55500d1092b4f323459625d433635f3559a058eef98140eb65b1082394994d72c5d329ee1 +SHA512 (uv-0.11.27.tar.gz) = a3a019d752d359487b330d05ab2a1dd8520f5b1e8f773c0dc5935693a9572d8b8f7b21e49e5fc76f9e2436aee3ced090e80dd0f3e1274caeb6558a67119b0a88 diff --git a/uv.spec b/uv.spec index 6fd3ea5..cb64787 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined el10} Name: uv -Version: 0.11.26 +Version: 0.11.27 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -65,12 +65,16 @@ Summary: An extremely fast Python package installer and resolver, written # BSD-2-Clause-Patent: # - test/ecosystem/github-wikidata-bot/ # BSD-3-Clause: +# - test/ecosystem/jupyterlab/ +# - test/ecosystem/pandas/ # - test/ecosystem/saleor/ # MIT: # - crates/uv-python/fetch-download-metadata.py is derived from # https://github.com/mitsuhiko/rye/tree/f9822267a7f00332d15be8551f89a212e7bc9017 # which was MIT. # - test/ecosystem/black/ +# - test/ecosystem/poetry/ +# - test/ecosystem/semantic-kernel/ # # Rust crates compiled into the executable contribute additional license terms. # To obtain the following list of licenses, build the package and note the @@ -148,6 +152,9 @@ Source1: uv.toml # Should uv.find_uv_bin() be able to find /usr/bin/uv? # https://github.com/astral-sh/uv/issues/4451 Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch +# Add license texts for new contents of test/ecosystem/ from PR#20068 +# https://github.com/astral-sh/uv/pull/20174 +Patch: %{url}/pull/20174.patch # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} @@ -645,10 +652,13 @@ skip="${skip-} --skip tests::built_by_uv_building" # dependency version differing from Cargo.lock. skip="${skip-} --skip base_client::tests::retried_status_codes" -# Harmless and trivial discrepancy in an error message: +# Harmless and trivial discrepancies in error messages: # 8 │- Caused by: error decoding response body for url (http://[LOCALHOST]/tqdm/) # 8 │+ Caused by: error decoding response body skip="${skip-} --skip network::retry_read_timeout_index" +# 9 │- Caused by: error decoding response body for url (http://[LOCALHOST]/) +# 9 │+ Caused by: error decoding response body +skip="${skip-} --skip network::retry_read_timeout_python_downloads_json" # These fail flakily: most frequently on ppc64le, but this seems to be just a # matter of luck, since we suspect a race condition. We have also seen failures From fca0e798ad68c63afbb16cc46affb4de08cfec97 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 8 Jul 2026 09:54:45 +0100 Subject: [PATCH 47/79] Update to 0.11.28 (close RHBZ#2497922) --- sources | 2 +- uv.spec | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/sources b/sources index 19d1ff0..d3b4af9 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.27.tar.gz) = a3a019d752d359487b330d05ab2a1dd8520f5b1e8f773c0dc5935693a9572d8b8f7b21e49e5fc76f9e2436aee3ced090e80dd0f3e1274caeb6558a67119b0a88 +SHA512 (uv-0.11.28.tar.gz) = b1e0468d714e70e7f4b1c9a3348ff8d7499cf463d9b59272347bfa38cc5d4d96c3913bf6c05222b26f098331cd84a3f495c4d5a4d872b45d5e735393cc3415ad diff --git a/uv.spec b/uv.spec index cb64787..070fad3 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined el10} Name: uv -Version: 0.11.27 +Version: 0.11.28 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From d0b910216ecd1b608cecff2ed50874ec976e6a1d Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 17 Jul 2026 08:19:10 +0000 Subject: [PATCH 48/79] Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild From f3fac865ad5f22d0c2cc4d028789cd789305d7c2 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sat, 18 Jul 2026 08:07:42 +0100 Subject: [PATCH 49/79] Trivial whitespace reformatting [skip changelog] --- uv.spec | 54 +++++++++++++++++++++++++++--------------------------- 1 file changed, 27 insertions(+), 27 deletions(-) diff --git a/uv.spec b/uv.spec index 070fad3..b5de105 100644 --- a/uv.spec +++ b/uv.spec @@ -113,33 +113,33 @@ Summary: An extremely fast Python package installer and resolver, written # Zlib # bzip2-1.0.6 License: %{shrink: - 0BSD AND - (0BSD OR Apache-2.0 OR MIT) AND - Apache-2.0 AND - (Apache-2.0 OR BSD-2-Clause) AND - (Apache-2.0 OR BSD-2-Clause OR MIT) AND - (Apache-2.0 OR BSL-1.0) AND - (Apache-2.0 OR ISC OR MIT) AND - (Apache-2.0 OR MIT) AND - (Apache-2.0 OR MIT OR Zlib) AND - (Apache-2.0 OR MIT-0) AND - (Apache-2.0 WITH LLVM-exception) AND - (Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT) AND - BSD-3-Clause AND - CC0-1.0 AND - CDLA-Permissive-2.0 AND - ISC AND - (LGPL-3.0-or-later OR MIT) AND - (LGPL-3.0-or-later OR MPL-2.0) AND - MIT AND - MIT-0 AND - (MIT OR Unlicense) AND - MPL-2.0 AND - Unicode-3.0 AND - Unicode-DFS-2016 AND - Zlib AND - bzip2-1.0.6 - } + 0BSD AND + (0BSD OR Apache-2.0 OR MIT) AND + Apache-2.0 AND + (Apache-2.0 OR BSD-2-Clause) AND + (Apache-2.0 OR BSD-2-Clause OR MIT) AND + (Apache-2.0 OR BSL-1.0) AND + (Apache-2.0 OR ISC OR MIT) AND + (Apache-2.0 OR MIT) AND + (Apache-2.0 OR MIT OR Zlib) AND + (Apache-2.0 OR MIT-0) AND + (Apache-2.0 WITH LLVM-exception) AND + (Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT) AND + BSD-3-Clause AND + CC0-1.0 AND + CDLA-Permissive-2.0 AND + ISC AND + (LGPL-3.0-or-later OR MIT) AND + (LGPL-3.0-or-later OR MPL-2.0) AND + MIT AND + MIT-0 AND + (MIT OR Unlicense) AND + MPL-2.0 AND + Unicode-3.0 AND + Unicode-DFS-2016 AND + Zlib AND + bzip2-1.0.6 + } # LICENSE.dependencies contains a full license breakdown URL: https://github.com/astral-sh/uv Source0: %{url}/archive/%{version}/uv-%{version}.tar.gz From 9df354a5935d9f5979e6a7f9f1f98b33500861a6 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sat, 18 Jul 2026 08:16:51 +0100 Subject: [PATCH 50/79] Avoid OOM on builders with relatively little total memory --- uv.spec | 22 +++++++++++++--------- 1 file changed, 13 insertions(+), 9 deletions(-) diff --git a/uv.spec b/uv.spec index b5de105..6ba0a89 100644 --- a/uv.spec +++ b/uv.spec @@ -168,15 +168,19 @@ ExcludeArch: %{ix86} # https://doc.rust-lang.org/rustc/codegen-options/index.html#debuginfo %global rustflags_debuginfo 1 -# As a separate limitation, memory exhaustion can occur on builders with very -# many CPUs. Typical workspace crates peak out at 2-4 GB per rustc invocation. -# The uv crate needs much more memory to compile and link, but in practice it -# is also compiled alone after all the other crates have finished, so it does -# not need to influence (and does not benefit from) this setting. This setting -# does not necessarily have to reflect the maximum memory required to compile a -# workspace crate; keeping it well above the average suffices in practice on -# many-core systems. Increase as needed. -%global _smp_tasksize_proc 4096 +# As a separate limitation, memory exhaustion (OOM) can occur during parallel +# portions of the build. +# - Because very many workspace crates can be built in parallel, builders with +# a very large number of CPUs may OOM. Typical workspace crates peak out at +# roughly 2–4 GB per rustc process. +# - The uv crate needs much more memory to compile and link, at least 8 GB, and +# when building the tests we may be building bin and lib versions at the same +# time, along with the it (integration test) crate, which is also rather +# large. This is a problem for “low memory” builders (<20 GB or so). +# Unfortunately, this means that we need to scale the memory per task based on +# the memory requirements of the top-level uv crate in order to avoid OOM on +# all kinds of builders. +%global _smp_tasksize_proc 10240 # Compilation may fail on builders with very many cores (e.g. 192 cores) due to # “too many open files.” Try to keep the files/core ratio from getting too low. From b1708e040e988ea5807df537ffeee35f72362391 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 22 Jul 2026 06:32:17 +0100 Subject: [PATCH 51/79] Update to 0.11.31 (close RHBZ#2501168) --- sources | 2 +- uv.spec | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/sources b/sources index d3b4af9..7ad4c3c 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.28.tar.gz) = b1e0468d714e70e7f4b1c9a3348ff8d7499cf463d9b59272347bfa38cc5d4d96c3913bf6c05222b26f098331cd84a3f495c4d5a4d872b45d5e735393cc3415ad +SHA512 (uv-0.11.31.tar.gz) = 7ae3789adccaf9fafcbb55843c719ff7167d33905587a34b2b423d04203204dcbfa9fcb8c6584ff10400d26ea71e8f44999c420511bd992ea7dfb25504b68d09 diff --git a/uv.spec b/uv.spec index 6ba0a89..6e0af43 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined el10} Name: uv -Version: 0.11.28 +Version: 0.11.31 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From 6110b4aebe95585bf6857eb4c6adc334546440cb Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 22 Jul 2026 07:17:53 +0100 Subject: [PATCH 52/79] Adjust the other_python_versions bcond to default off on all EPELs [skip changelog] --- uv.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/uv.spec b/uv.spec index 6e0af43..90199a3 100644 --- a/uv.spec +++ b/uv.spec @@ -2,7 +2,7 @@ # Should we run tests that require specific Python interpreter versions # (major.minor, not major.minor.patch)? This adds a few dozen tests, but adds # BuildRequires on more Python interpreters (which aren’t available in EPEL). -%bcond other_python_versions %{undefined el10} +%bcond other_python_versions %{undefined epel} Name: uv Version: 0.11.31 From 6e7b6c01ad0794e214459770352a154e00e32185 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 22 Jul 2026 07:19:47 +0100 Subject: [PATCH 53/79] Use pyproject long options --- uv.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/uv.spec b/uv.spec index 90199a3..15c8874 100644 --- a/uv.spec +++ b/uv.spec @@ -555,7 +555,7 @@ sed --regexp-extended --in-place \ %install %pyproject_install -%pyproject_save_files -L uv +%pyproject_save_files --no-assert-license uv if [ '%{python3_sitearch}' != '%{python3_sitelib}' ] then From 1e53b4b6484ade65dcf6103f7afd362b2a612aed Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 22 Jul 2026 07:22:14 +0100 Subject: [PATCH 54/79] Assert that the .dist-info directory contains license files --- uv.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/uv.spec b/uv.spec index 15c8874..39ea520 100644 --- a/uv.spec +++ b/uv.spec @@ -555,7 +555,7 @@ sed --regexp-extended --in-place \ %install %pyproject_install -%pyproject_save_files --no-assert-license uv +%pyproject_save_files --assert-license uv if [ '%{python3_sitearch}' != '%{python3_sitelib}' ] then From 958b78c7977e19902abda38e660fc073d74a5655 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 22 Jul 2026 07:24:40 +0100 Subject: [PATCH 55/79] Use the provisional pyproject declarative buildsystem --- uv.spec | 23 ++++++++--------------- 1 file changed, 8 insertions(+), 15 deletions(-) diff --git a/uv.spec b/uv.spec index 39ea520..331ca44 100644 --- a/uv.spec +++ b/uv.spec @@ -156,6 +156,9 @@ Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch # https://github.com/astral-sh/uv/pull/20174 Patch: %{url}/pull/20174.patch +BuildSystem: pyproject +BuildOption(install): --assert-license uv + # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} @@ -354,9 +357,7 @@ Requires: uv = %{version}-%{release} This package provides an importable Python module for uv. -%prep -%autosetup -p1 - +%prep -a # Collect license files of vendored dependencies in the main source archive install -D --preserve-timestamps --mode=0644 \ --target=LICENSE.bundled/packaging \ @@ -531,7 +532,7 @@ sed --regexp-extended --in-place \ %cargo_prep -%generate_buildrequires +%generate_buildrequires -p # For unclear reasons, maturin checks for all crate dependencies when it is # invoked as part of %%pyproject_buildrequires – including those corresponding # to optional features. @@ -543,20 +544,14 @@ sed --regexp-extended --in-place \ # Since maturin always checks for dev-dependencies, we need -t so that they are # generated even when the “check” bcond is disabled. %cargo_generate_buildrequires -a -t -%pyproject_buildrequires -%build -%pyproject_wheel - +%build -a %{cargo_license_summary} %{cargo_license} > LICENSE.dependencies -%install -%pyproject_install -%pyproject_save_files --assert-license uv - +%install -a if [ '%{python3_sitearch}' != '%{python3_sitelib}' ] then # Maturin is really designed to build compiled Python extensions, but (when @@ -587,7 +582,7 @@ install -D --preserve-timestamps --mode=0644 \ --target='%{buildroot}%{_sysconfdir}/uv' '%{SOURCE1}' -%check +%check -a %if %{with check} # These tests rely on debug assertions, and fail when tests are compiled in # release mode: @@ -683,8 +678,6 @@ skip="${skip-} --skip user_agent_version::test_user_agent_has_version" %cargo_test -- -- --exact ${skip-} %endif -%pyproject_check_import - %files %license LICENSE-APACHE LICENSE-MIT LICENSE.dependencies LICENSE.bundled/ From 97c5cc15eec2ba5cde5fbebeb4bfceb3b1440ce1 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Fri, 24 Jul 2026 08:14:45 +0100 Subject: [PATCH 56/79] Skip some tests related to managed interpreters on riscv64 --- uv.spec | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/uv.spec b/uv.spec index 331ca44..19e1c77 100644 --- a/uv.spec +++ b/uv.spec @@ -615,6 +615,16 @@ skip="${skip-} --skip python_list::python_list_with_mirrors" # This might be worth reporting upstream, but is not a serious issue. skip="${skip-} --skip python_pin::python_pin_resolve" %endif +%ifarch riscv64 +# These expect managed interpreters of the form +# cpython-3.##-linux-riscv64gc-any, but crates/uv-python/download-metadata.json +# only has them for cpython-3.##-linux-riscv64-gnu. It’s not weird to find +# holes in the managed interpreter support matrix for less common +# architectures. +skip="${skip-} --skip python_find::python_find" +skip="${skip-} --skip python_list::python_list" +skip="${skip-} --skip python_pin::python_pin_resolve" +%endif # Test registry_client::tests::test_redirect_to_server_with_credentials is # flaky # https://github.com/astral-sh/uv/issues/16447 From 4bd686691f8a8062d302248d884ff601aa1a1417 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Fri, 24 Jul 2026 06:48:49 +0100 Subject: [PATCH 57/79] Update to 0.11.32 (close RHBZ#2506667) --- sources | 2 +- uv.spec | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/sources b/sources index 7ad4c3c..ea9a774 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.31.tar.gz) = 7ae3789adccaf9fafcbb55843c719ff7167d33905587a34b2b423d04203204dcbfa9fcb8c6584ff10400d26ea71e8f44999c420511bd992ea7dfb25504b68d09 +SHA512 (uv-0.11.32.tar.gz) = cd1c810400b0712f93fa8dd56ca55b726c22e33f8655ab48011f34f8c2a69d8f517ccd758f0cc0a3a293ee1eae2bac994577073d3e2cd7449ff7a43ba2f88194 diff --git a/uv.spec b/uv.spec index 19e1c77..ad26642 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.11.31 +Version: 0.11.32 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From e0e68f579822eba4c8763485dd3a8e598e77a037 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Mon, 27 Jul 2026 06:57:16 +0100 Subject: [PATCH 58/79] Skip a test that fails in emulated chroots --- uv.spec | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/uv.spec b/uv.spec index ad26642..0a147d9 100644 --- a/uv.spec +++ b/uv.spec @@ -625,6 +625,15 @@ skip="${skip-} --skip python_find::python_find" skip="${skip-} --skip python_list::python_list" skip="${skip-} --skip python_pin::python_pin_resolve" %endif + +# It’s not clear what causes the trivial discrepancy, but we find that this +# fails when building in qemu-user-static emulated chroots. +# 4 │- Caused by: Failed to query Python interpreter at `[TEMP_DIR]/bar` +# 5 │- Caused by: [PERMISSION DENIED] +# 4 │+ Caused by: Querying Python at `[TEMP_DIR]/bar` failed with +# exit status exit status: 127 +skip="${skip-} --skip python_find::python_find_path" + # Test registry_client::tests::test_redirect_to_server_with_credentials is # flaky # https://github.com/astral-sh/uv/issues/16447 From 3683e38d1d9e4d46f9cc2b56a2491fcb7e49f8b7 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Fri, 31 Jul 2026 07:27:17 +0100 Subject: [PATCH 59/79] Update to 0.11.33 --- sources | 2 +- uv.spec | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/sources b/sources index ea9a774..7f2a53e 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.32.tar.gz) = cd1c810400b0712f93fa8dd56ca55b726c22e33f8655ab48011f34f8c2a69d8f517ccd758f0cc0a3a293ee1eae2bac994577073d3e2cd7449ff7a43ba2f88194 +SHA512 (uv-0.11.33.tar.gz) = eebc671598b627b9c152da0bad7b3a723788d517b919b0be6db7bea15f89188df613ec04e0b5f1ce189d333faaabbda6649c0ef2f031bd6159cb36aac1c409b6 diff --git a/uv.spec b/uv.spec index 0a147d9..f47bc93 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.11.32 +Version: 0.11.33 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From 3cbb6c04d81ed6ba25abacde4b594954181607b6 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Fri, 31 Jul 2026 16:29:06 +0100 Subject: [PATCH 60/79] Update to 0.12.0 --- sources | 2 +- uv.spec | 14 ++------------ 2 files changed, 3 insertions(+), 13 deletions(-) diff --git a/sources b/sources index 7f2a53e..ee4c492 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.11.33.tar.gz) = eebc671598b627b9c152da0bad7b3a723788d517b919b0be6db7bea15f89188df613ec04e0b5f1ce189d333faaabbda6649c0ef2f031bd6159cb36aac1c409b6 +SHA512 (uv-0.12.0.tar.gz) = 9dfcb42b4d74c9f26dbb4e6b5ed1a424aafd3c4c2920766682f9d0fa5e54f52a6e9c76fd8d78bc10f6bc0054daed7e339bb01cc79d5114fd51cfc67a27186558 diff --git a/uv.spec b/uv.spec index f47bc93..7d06664 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.11.33 +Version: 0.12.0 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -111,7 +111,6 @@ Summary: An extremely fast Python package installer and resolver, written # Unicode-3.0 # Unlicense OR MIT # Zlib -# bzip2-1.0.6 License: %{shrink: 0BSD AND (0BSD OR Apache-2.0 OR MIT) AND @@ -137,8 +136,7 @@ License: %{shrink: MPL-2.0 AND Unicode-3.0 AND Unicode-DFS-2016 AND - Zlib AND - bzip2-1.0.6 + Zlib } # LICENSE.dependencies contains a full license breakdown URL: https://github.com/astral-sh/uv @@ -427,14 +425,6 @@ tomcli set Cargo.toml append workspace.exclude crates/uv-bench # needed here. It also brings extra dependencies that we would prefer to avoid. tomcli set Cargo.toml append workspace.exclude crates/uv-dev -# Do not request static linking of anything (particularly, liblzma) -tomcli set Cargo.toml lists delitem \ - workspace.dependencies.xz2.features 'static' -tomcli set crates/uv/Cargo.toml lists delitem \ - features.default 'uv-distribution/static' -tomcli set crates/uv-distribution/Cargo.toml del features.static -tomcli set crates/uv-extract/Cargo.toml del features.static - # Disable several default features that control which tests are compiled and # executed, and which are not usable in offline builds: # From 7f903f9dcee7f7a5ae7d45c5e906da9eba520288 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sun, 2 Aug 2026 11:58:22 +0100 Subject: [PATCH 61/79] Update to 0.12.1 (close RHBZ#2509887) --- sources | 2 +- uv-0.12.1-revert-blake2-beta.patch | 11 +++++++++++ uv.spec | 15 ++++++++++++++- 3 files changed, 26 insertions(+), 2 deletions(-) create mode 100644 uv-0.12.1-revert-blake2-beta.patch diff --git a/sources b/sources index ee4c492..8c0e819 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.12.0.tar.gz) = 9dfcb42b4d74c9f26dbb4e6b5ed1a424aafd3c4c2920766682f9d0fa5e54f52a6e9c76fd8d78bc10f6bc0054daed7e339bb01cc79d5114fd51cfc67a27186558 +SHA512 (uv-0.12.1.tar.gz) = 15c84d4b719295c1d9fca178025317d1b808f4c34a572609b78e35382bb12abdc4ba7a3b2bd1bc5576763b655b34b222be15f99c3481419f92a5f74e460ef96f diff --git a/uv-0.12.1-revert-blake2-beta.patch b/uv-0.12.1-revert-blake2-beta.patch new file mode 100644 index 0000000..805ef98 --- /dev/null +++ b/uv-0.12.1-revert-blake2-beta.patch @@ -0,0 +1,11 @@ +diff -Naur uv-0.12.1-original/crates/uv-extract/src/hash.rs uv-0.12.1/crates/uv-extract/src/hash.rs +--- uv-0.12.1-original/crates/uv-extract/src/hash.rs 2026-07-31 20:05:57.000000000 +0100 ++++ uv-0.12.1/crates/uv-extract/src/hash.rs 2026-08-02 11:53:13.406289238 +0100 +@@ -1,4 +1,6 @@ +-use sha2::{Digest, digest::consts::U32}; ++// BLAKE2 still uses the `digest` 0.10 trait, while MD5 and SHA-2 use 0.11. ++use blake2::digest::{Digest as _, consts::U32}; ++use sha2::Digest; + use std::pin::Pin; + use std::task::{Context, Poll}; + use tokio::io::{AsyncReadExt, ReadBuf}; diff --git a/uv.spec b/uv.spec index 7d06664..ccb997f 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.12.0 +Version: 0.12.1 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -150,6 +150,10 @@ Source1: uv.toml # Should uv.find_uv_bin() be able to find /usr/bin/uv? # https://github.com/astral-sh/uv/issues/4451 Patch: 0001-Downstream-patch-always-find-the-system-wide-uv-exec.patch +# Downstream-only: revert source-code changes from “Upgrade BLAKE2 to unify +# hashing digest versions”, https://github.com/astral-sh/uv/pull/20834. We do +# not wish to upgrade rust-blake2 to a pre-release. +Patch: uv-0.12.1-revert-blake2-beta.patch # Add license texts for new contents of test/ecosystem/ from PR#20068 # https://github.com/astral-sh/uv/pull/20174 Patch: %{url}/pull/20174.patch @@ -519,6 +523,15 @@ sed --regexp-extended --in-place \ 's/^(tikv-jemallocator\b.*version = ")0\.6\.0"/\1>=0.6.0, <0.8.0"/' \ crates/uv-performance-memory-allocator/Cargo.toml +# blake2 +# wanted: 0.11.0-rc.6 +# currently packaged: 0.10.6 +# https://github.com/astral-sh/uv/pull/19735 +# Downstream-only: revert “Upgrade BLAKE2 to unify hashing digest versions”, +# https://github.com/astral-sh/uv/pull/20834. We do not wish to upgrade +# rust-blake2 to a pre-release. There is an anccompanying source-code patch. +tomcli set Cargo.toml str workspace.dependencies.blake2.version 0.10.6 + %cargo_prep From 62bd08e26e6780b14f11aefff1138cfbf8d63b23 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Tue, 4 Aug 2026 23:28:34 +0100 Subject: [PATCH 62/79] Document bundling of rust-netrc crate --- uv.spec | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/uv.spec b/uv.spec index ccb997f..c883739 100644 --- a/uv.spec +++ b/uv.spec @@ -45,6 +45,7 @@ Summary: An extremely fast Python package installer and resolver, written # MIT # - crates/uv-virtualenv/src/activator/ is vendored and forked from # python3dist(virtualenv) +# - crates/uv-netrc/ is vencored from crate(rust-netrc) # # Additionally, the following are bundled/forked but happen to be under the # same (Apache-2.0 OR MIT) terms as uv itself: @@ -274,6 +275,16 @@ Provides: bundled(crate(r-shquote)) = 0.1.1 # appear to be any prospect of unbundling. Provides: bundled(crate(keyring)) = 4.0.0~rc2 +# crates/uv-netrc +# From crates/uv-netrc/README.md, “This crate vendors the rust-netrc parser for +# use by uv. The source was vendored from gribouille/netrc, as published in +# rust-netrc 0.1.2[…]” +# +# Upstream justifies the bundling in +# https://github.com/astral-sh/uv/pull/19409, and the mandatory +# path-to-unbundling query appears in a comment on that PR. +Provides: bundled(crate(rust-netrc)) = 0.1.2 + # The contents of crates/uv-virtualenv/src/activator/ are a bundled and # slightly forked copy of a subset of https://pypi.org/project/virtualenv; see # https://github.com/pypa/virtualenv/tree/main/src/virtualenv/activation. From 049d34581dd3218022c789ccb156813d4d9cd5bb Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 5 Aug 2026 06:57:56 +0100 Subject: [PATCH 63/79] More spec-file comment improvements --- uv.spec | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/uv.spec b/uv.spec index c883739..faf62c8 100644 --- a/uv.spec +++ b/uv.spec @@ -45,7 +45,7 @@ Summary: An extremely fast Python package installer and resolver, written # MIT # - crates/uv-virtualenv/src/activator/ is vendored and forked from # python3dist(virtualenv) -# - crates/uv-netrc/ is vencored from crate(rust-netrc) +# - crates/uv-netrc/ is vendored from crate(rust-netrc) # # Additionally, the following are bundled/forked but happen to be under the # same (Apache-2.0 OR MIT) terms as uv itself: @@ -281,8 +281,11 @@ Provides: bundled(crate(keyring)) = 4.0.0~rc2 # rust-netrc 0.1.2[…]” # # Upstream justifies the bundling in -# https://github.com/astral-sh/uv/pull/19409, and the mandatory -# path-to-unbundling query appears in a comment on that PR. +# https://github.com/astral-sh/uv/pull/19409: they want unreleased bug fixes, +# including those pertaining to https://github.com/astral-sh/uv/issues/16083, +# and to avoid a dependency on thiserror v1. In response to the mandatory +# query, they report they are open to de-vendoring if a new rust-netrc release +# with the desired changes appears. Provides: bundled(crate(rust-netrc)) = 0.1.2 # The contents of crates/uv-virtualenv/src/activator/ are a bundled and From cb8c37590766e95fd2e179086e17359eb6fe7cb0 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 5 Aug 2026 07:00:49 +0100 Subject: [PATCH 64/79] Ship the license file for the vendored rust-netrc --- uv.spec | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/uv.spec b/uv.spec index faf62c8..aed7ceb 100644 --- a/uv.spec +++ b/uv.spec @@ -374,7 +374,7 @@ This package provides an importable Python module for uv. %prep -a -# Collect license files of vendored dependencies in the main source archive +# Collect license files of vendored dependencies install -D --preserve-timestamps --mode=0644 \ --target=LICENSE.bundled/packaging \ crates/uv-python/python/packaging/LICENSE.* @@ -387,6 +387,8 @@ install -D --preserve-timestamps --mode=0644 \ crates/uv-build-frontend/src/pipreqs/LICENSE install -D --preserve-timestamps --mode=0644 \ --target=LICENSE.bundled/ripunzip crates/uv-extract/src/vendor/LICENSE +install -D --preserve-timestamps --mode=0644 \ + --target=LICENSE.bundled/rust-netrc crates/uv-netrc/LICENSE # The original license text from rattler_installs_packages is present in a # comment, but we want it in a separate file so we can ensure it is present in # the binary RPM. From 3e1297d8471684a3bde5b8fefdb537a598e460e9 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 5 Aug 2026 08:40:26 +0100 Subject: [PATCH 65/79] Skip another test that flakes due to racy env-vars --- uv.spec | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/uv.spec b/uv.spec index aed7ceb..26fd457 100644 --- a/uv.spec +++ b/uv.spec @@ -712,6 +712,13 @@ skip="${skip-} --skip network::retry_read_timeout_python_downloads_json" skip="${skip-} --skip user_agent_version::test_user_agent_has_linehaul" skip="${skip-} --skip user_agent_version::test_user_agent_has_subcommand" skip="${skip-} --skip user_agent_version::test_user_agent_has_version" +# Similarly, with an error like: +# Client::new(): reqwest::Error { +# kind: Builder, +# source: General("No CA certificates were loaded from the system") +# } +# There are probably more of these. +skip="${skip-} --skip retry::tests::retried_status_codes" %cargo_test -- -- --exact ${skip-} %endif From cb3df8bce7ac4d252b9a75005d9f854124a73d1b Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 6 Aug 2026 07:22:38 +0100 Subject: [PATCH 66/79] Update to 0.12.2 (close RHBZ#2511719) --- sources | 2 +- uv.spec | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/sources b/sources index 8c0e819..a72ff96 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.12.1.tar.gz) = 15c84d4b719295c1d9fca178025317d1b808f4c34a572609b78e35382bb12abdc4ba7a3b2bd1bc5576763b655b34b222be15f99c3481419f92a5f74e460ef96f +SHA512 (uv-0.12.2.tar.gz) = 4058b81df286d5702278c7a3315dc3df96aae15ae255c4cb71fa293aa9d8519842d58c8d1a00b3c2a6c33443449b0d975bc0122e972a05c9ce023e00ee260575 diff --git a/uv.spec b/uv.spec index 26fd457..8b31116 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.12.1 +Version: 0.12.2 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From ca46850e729f91fdd06684e01451d82807928c7a Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sat, 8 Aug 2026 05:55:28 +0100 Subject: [PATCH 67/79] Update to 0.12.3 (close RHBZ#2512634) --- sources | 2 +- uv.spec | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/sources b/sources index a72ff96..ce4d7d8 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.12.2.tar.gz) = 4058b81df286d5702278c7a3315dc3df96aae15ae255c4cb71fa293aa9d8519842d58c8d1a00b3c2a6c33443449b0d975bc0122e972a05c9ce023e00ee260575 +SHA512 (uv-0.12.3.tar.gz) = a4933b9b9b852dee2485800ad82ee3be111a4a5a437ab32d5064cfd4004e124ba733294a546a097379c74cf1fc234d1da0488aec7725037c7b967ec1aa862a71 diff --git a/uv.spec b/uv.spec index 8b31116..49a17fc 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.12.2 +Version: 0.12.3 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From 247904f9a8ae91df0730d2e1b950d15f3848d6f4 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Mon, 24 Aug 2026 07:33:31 +0100 Subject: [PATCH 68/79] =?UTF-8?q?Don=E2=80=99t=20explicitly=20lower-bound?= =?UTF-8?q?=20cargo-rpm-macros=20version?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit [skip changelog] --- uv.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/uv.spec b/uv.spec index 49a17fc..3583aa3 100644 --- a/uv.spec +++ b/uv.spec @@ -192,7 +192,7 @@ ExcludeArch: %{ix86} # “too many open files.” Try to keep the files/core ratio from getting too low. %global _smp_ncpus_max 48 -BuildRequires: cargo-rpm-macros >= 24 +BuildRequires: cargo-rpm-macros BuildRequires: rust2rpm-helper BuildRequires: tomcli %if %{with check} && %{with other_python_versions} From 443167d26102e93bf972bef2464a92acc646e517 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 2 Sep 2026 12:04:17 +0100 Subject: [PATCH 69/79] Update to 0.12.4 --- sources | 2 +- uv.spec | 9 ++++++++- 2 files changed, 9 insertions(+), 2 deletions(-) diff --git a/sources b/sources index ce4d7d8..7e20d9f 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.12.3.tar.gz) = a4933b9b9b852dee2485800ad82ee3be111a4a5a437ab32d5064cfd4004e124ba733294a546a097379c74cf1fc234d1da0488aec7725037c7b967ec1aa862a71 +SHA512 (uv-0.12.4.tar.gz) = dec7f7f6d9f7e96198eae29b1755f3ac489b14b45a0f2e7e4e55ecca70d68aacdf4c0674f60bd2f7ad96d5d77ee227798202608658c9e797c895e716dafbc63e diff --git a/uv.spec b/uv.spec index 3583aa3..66ea1ff 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.12.3 +Version: 0.12.4 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -548,6 +548,13 @@ sed --regexp-extended --in-place \ # rust-blake2 to a pre-release. There is an anccompanying source-code patch. tomcli set Cargo.toml str workspace.dependencies.blake2.version 0.10.6 +# tar-codec +# wanted: 0.0.13 +# currently packaged: 0.0.14 +# A subsequent uv release will want the newer version, and it’s +# backwards-compatible enough in practice. +tomcli set Cargo.toml str workspace.dependencies.tar-codec.version 0.0.14 + %cargo_prep From b380b8282ce8c007dc153143998ed3b1d2819d09 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 2 Sep 2026 21:24:50 +0100 Subject: [PATCH 70/79] Update to 0.12.5 --- sources | 2 +- uv.spec | 6 ++++-- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/sources b/sources index 7e20d9f..498e6ab 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.12.4.tar.gz) = dec7f7f6d9f7e96198eae29b1755f3ac489b14b45a0f2e7e4e55ecca70d68aacdf4c0674f60bd2f7ad96d5d77ee227798202608658c9e797c895e716dafbc63e +SHA512 (uv-0.12.5.tar.gz) = 680253f889ef2a598071aeaeb51581b2b49a0aadf0f450d1c69bd60c267c71b925f6318e93572861f4410cbd3613b6fded10375821ce4376458249c75269b774 diff --git a/uv.spec b/uv.spec index 66ea1ff..deaa088 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.12.4 +Version: 0.12.5 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -89,6 +89,7 @@ Summary: An extremely fast Python package installer and resolver, written # 0BSD OR MIT OR Apache-2.0 # Apache-2.0 # Apache-2.0 AND ISC AND (MIT OR Apache-2.0) +# Apache-2.0 OR Apache-2.0 WITH LLVM-exception # Apache-2.0 OR BSD-2-Clause # Apache-2.0 OR BSL-1.0 # Apache-2.0 OR ISC OR MIT @@ -116,6 +117,8 @@ License: %{shrink: 0BSD AND (0BSD OR Apache-2.0 OR MIT) AND Apache-2.0 AND + (Apache-2.0 OR Apache-2.0 WITH LLVM-exception OR MIT) AND + (Apache-2.0 OR Apache-2.0 WITH LLVM-exception) AND (Apache-2.0 OR BSD-2-Clause) AND (Apache-2.0 OR BSD-2-Clause OR MIT) AND (Apache-2.0 OR BSL-1.0) AND @@ -124,7 +127,6 @@ License: %{shrink: (Apache-2.0 OR MIT OR Zlib) AND (Apache-2.0 OR MIT-0) AND (Apache-2.0 WITH LLVM-exception) AND - (Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT) AND BSD-3-Clause AND CC0-1.0 AND CDLA-Permissive-2.0 AND From 85c10fdc371739e7a3fb6022158d0b4b82088be8 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 2 Sep 2026 23:06:18 +0100 Subject: [PATCH 71/79] Update to 0.12.6 --- 21433.patch | 34 ++++++++++++++++++++++++++++++++++ sources | 2 +- uv.spec | 5 ++++- 3 files changed, 39 insertions(+), 2 deletions(-) create mode 100644 21433.patch diff --git a/21433.patch b/21433.patch new file mode 100644 index 0000000..8d08429 --- /dev/null +++ b/21433.patch @@ -0,0 +1,34 @@ +From 37b12e28bfa28593e477444467a571bda0656741 Mon Sep 17 00:00:00 2001 +From: "Benjamin A. Beasley" +Date: Thu, 3 Sep 2026 06:28:52 +0100 +Subject: [PATCH] Gate dirhash::tests::test_vectors_json on test-pypi feature + +--- + crates/uv-extract/Cargo.toml | 1 + + crates/uv-extract/src/dirhash.rs | 1 + + 2 files changed, 2 insertions(+) + +diff --git a/crates/uv-extract/Cargo.toml b/crates/uv-extract/Cargo.toml +index abd7bbb9895..7df1a21412f 100644 +--- a/crates/uv-extract/Cargo.toml ++++ b/crates/uv-extract/Cargo.toml +@@ -53,6 +53,7 @@ serde_json = { workspace = true } + + [features] + default = [] ++test-pypi = [] + + [package.metadata.cargo-shear] + # NOTE: `async-compression` owns the actual Deflate codec, but we need to +diff --git a/crates/uv-extract/src/dirhash.rs b/crates/uv-extract/src/dirhash.rs +index 76a0300ca51..ad0ce9b78f2 100644 +--- a/crates/uv-extract/src/dirhash.rs ++++ b/crates/uv-extract/src/dirhash.rs +@@ -804,6 +804,7 @@ mod tests { + dirhash: String, + } + ++ #[cfg(feature = "test-pypi")] + // `../test_vectors/test_vectors.json` contains a series of input trees and hashes, which is + // generated by `cargo dev generate-dirhash-test-vectors`. This tests both `dirhash_path` and + // `DirhashTree` from this file, and also the `dirhash.py` Python implementation, so we're diff --git a/sources b/sources index 498e6ab..45619da 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.12.5.tar.gz) = 680253f889ef2a598071aeaeb51581b2b49a0aadf0f450d1c69bd60c267c71b925f6318e93572861f4410cbd3613b6fded10375821ce4376458249c75269b774 +SHA512 (uv-0.12.6.tar.gz) = afe6f5788468168f9380122073a8e96b88c14def80df8cd253cd64e4cc28f16da76137d90a73b8bd1e6cd93c0858701002161e53235f55749ac11eaa14b14000 diff --git a/uv.spec b/uv.spec index deaa088..95c0526 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.12.5 +Version: 0.12.6 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -160,6 +160,9 @@ Patch: uv-0.12.1-revert-blake2-beta.patch # Add license texts for new contents of test/ecosystem/ from PR#20068 # https://github.com/astral-sh/uv/pull/20174 Patch: %{url}/pull/20174.patch +# Gate dirhash::tests::test_vectors_json on test-pypi feature +# https://github.com/astral-sh/uv/pull/21433 +Patch: %{url}/pull/21433.patch BuildSystem: pyproject BuildOption(install): --assert-license uv From 528a5b76b3234a0fe89cb083a3dc76c877851c5b Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 3 Sep 2026 07:36:47 +0100 Subject: [PATCH 72/79] Update to 0.12.7 --- sources | 2 +- uv.spec | 10 +--------- 2 files changed, 2 insertions(+), 10 deletions(-) diff --git a/sources b/sources index 45619da..bc35ac8 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.12.6.tar.gz) = afe6f5788468168f9380122073a8e96b88c14def80df8cd253cd64e4cc28f16da76137d90a73b8bd1e6cd93c0858701002161e53235f55749ac11eaa14b14000 +SHA512 (uv-0.12.7.tar.gz) = 7f9bd1aef6c285aedd3fe588a5f70e0458f85f6db14f0368ea24c5524fd66990510e0d5624a7faf48091a3dc73ff66ac52ab9a6ed571a10cca272b9588fb1aff diff --git a/uv.spec b/uv.spec index 95c0526..73473b2 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.12.6 +Version: 0.12.7 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -547,19 +547,11 @@ sed --regexp-extended --in-place \ # blake2 # wanted: 0.11.0-rc.6 # currently packaged: 0.10.6 -# https://github.com/astral-sh/uv/pull/19735 # Downstream-only: revert “Upgrade BLAKE2 to unify hashing digest versions”, # https://github.com/astral-sh/uv/pull/20834. We do not wish to upgrade # rust-blake2 to a pre-release. There is an anccompanying source-code patch. tomcli set Cargo.toml str workspace.dependencies.blake2.version 0.10.6 -# tar-codec -# wanted: 0.0.13 -# currently packaged: 0.0.14 -# A subsequent uv release will want the newer version, and it’s -# backwards-compatible enough in practice. -tomcli set Cargo.toml str workspace.dependencies.tar-codec.version 0.0.14 - %cargo_prep From 3f02175d5ea0c8256d73f0f9fd6e092b8ebe1aae Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 3 Sep 2026 19:01:28 +0100 Subject: [PATCH 73/79] Improved patch for dirhash tests --- 21433.patch | 34 ----------------------- 21434.patch | 78 +++++++++++++++++++++++++++++++++++++++++++++++++++++ uv.spec | 6 ++--- 3 files changed, 81 insertions(+), 37 deletions(-) delete mode 100644 21433.patch create mode 100644 21434.patch diff --git a/21433.patch b/21433.patch deleted file mode 100644 index 8d08429..0000000 --- a/21433.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 37b12e28bfa28593e477444467a571bda0656741 Mon Sep 17 00:00:00 2001 -From: "Benjamin A. Beasley" -Date: Thu, 3 Sep 2026 06:28:52 +0100 -Subject: [PATCH] Gate dirhash::tests::test_vectors_json on test-pypi feature - ---- - crates/uv-extract/Cargo.toml | 1 + - crates/uv-extract/src/dirhash.rs | 1 + - 2 files changed, 2 insertions(+) - -diff --git a/crates/uv-extract/Cargo.toml b/crates/uv-extract/Cargo.toml -index abd7bbb9895..7df1a21412f 100644 ---- a/crates/uv-extract/Cargo.toml -+++ b/crates/uv-extract/Cargo.toml -@@ -53,6 +53,7 @@ serde_json = { workspace = true } - - [features] - default = [] -+test-pypi = [] - - [package.metadata.cargo-shear] - # NOTE: `async-compression` owns the actual Deflate codec, but we need to -diff --git a/crates/uv-extract/src/dirhash.rs b/crates/uv-extract/src/dirhash.rs -index 76a0300ca51..ad0ce9b78f2 100644 ---- a/crates/uv-extract/src/dirhash.rs -+++ b/crates/uv-extract/src/dirhash.rs -@@ -804,6 +804,7 @@ mod tests { - dirhash: String, - } - -+ #[cfg(feature = "test-pypi")] - // `../test_vectors/test_vectors.json` contains a series of input trees and hashes, which is - // generated by `cargo dev generate-dirhash-test-vectors`. This tests both `dirhash_path` and - // `DirhashTree` from this file, and also the `dirhash.py` Python implementation, so we're diff --git a/21434.patch b/21434.patch new file mode 100644 index 0000000..8a43884 --- /dev/null +++ b/21434.patch @@ -0,0 +1,78 @@ +From 9ded1ff23cb5d9c78c615ab0bb026942fac5d128 Mon Sep 17 00:00:00 2001 +From: Charlie Marsh +Date: Thu, 3 Sep 2026 07:24:08 -0400 +Subject: [PATCH] Remove Python invocation from dirhash tests + +--- + crates/uv-extract/src/dirhash.rs | 27 +++-------------------- + crates/uv-extract/test_vectors/dirhash.py | 5 +---- + 2 files changed, 4 insertions(+), 28 deletions(-) + +diff --git a/crates/uv-extract/src/dirhash.rs b/crates/uv-extract/src/dirhash.rs +index 76a0300ca51..943e13bd1fb 100644 +--- a/crates/uv-extract/src/dirhash.rs ++++ b/crates/uv-extract/src/dirhash.rs +@@ -519,7 +519,6 @@ mod tests { + + use super::*; + use std::cmp; +- use std::process::Command; + use std::task::{Context, Poll}; + + #[test] +@@ -806,10 +805,9 @@ mod tests { + + // `../test_vectors/test_vectors.json` contains a series of input trees and hashes, which is + // generated by `cargo dev generate-dirhash-test-vectors`. This tests both `dirhash_path` and +- // `DirhashTree` from this file, and also the `dirhash.py` Python implementation, so we're +- // testing that three different implementations agree. +- #[tokio::test] +- async fn test_vectors_json() -> anyhow::Result<()> { ++ // `DirhashTree` against the committed hashes. ++ #[test] ++ fn test_vectors_json() -> anyhow::Result<()> { + let test_vectors: Vec = + serde_json::from_str(include_str!("../test_vectors/test_vectors.json"))?; + for JsonTestVector { input, dirhash } in &test_vectors { +@@ -828,25 +826,6 @@ mod tests { + dirhash.as_str(), + dirhash_path(tempdir.path())?.to_hex().as_str(), + ); +- +- // Check the Python implementation, which also reads the FS. +- let python_script = Path::new(env!("CARGO_MANIFEST_DIR")) +- .join("test_vectors") +- .join("dirhash.py"); +- let output = Command::new("uv") +- .args(["run", "--locked", "--script"]) +- .arg(python_script) +- .arg(tempdir.path()) +- .output()?; +- assert!(output.status.success()); +- // This script's output is formatted like `md5sum` or `b3sum`, with each line including +- // a hash, a couple spaces, and a path. With only one path arg, there will be only one +- // line. +- let python_dirhash = std::str::from_utf8(&output.stdout)? +- .split_whitespace() +- .next() +- .unwrap(); +- assert_eq!(dirhash.as_str(), python_dirhash); + } + Ok(()) + } +diff --git a/crates/uv-extract/test_vectors/dirhash.py b/crates/uv-extract/test_vectors/dirhash.py +index fde1339670e..73ef480ca8a 100755 +--- a/crates/uv-extract/test_vectors/dirhash.py ++++ b/crates/uv-extract/test_vectors/dirhash.py +@@ -10,10 +10,7 @@ + # exclude-newer = "P7D" + # /// + +-"""Independent Python implementation of ``uv_extract::dirhash``. +- +-The Rust ``test_vectors_json`` test case exercises this implementation in CI. +-""" ++"""Independent Python implementation of ``uv_extract::dirhash``.""" + + import sys + from pathlib import Path diff --git a/uv.spec b/uv.spec index 73473b2..e45492a 100644 --- a/uv.spec +++ b/uv.spec @@ -160,9 +160,9 @@ Patch: uv-0.12.1-revert-blake2-beta.patch # Add license texts for new contents of test/ecosystem/ from PR#20068 # https://github.com/astral-sh/uv/pull/20174 Patch: %{url}/pull/20174.patch -# Gate dirhash::tests::test_vectors_json on test-pypi feature -# https://github.com/astral-sh/uv/pull/21433 -Patch: %{url}/pull/21433.patch +# Remove Python invocation from dirhash tests +# https://github.com/astral-sh/uv/pull/21434 +Patch: %{url}/pull/21434.patch BuildSystem: pyproject BuildOption(install): --assert-license uv From cbdcf5463b923a173db91eaaf5c1092f2453548b Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 3 Sep 2026 19:10:37 +0100 Subject: [PATCH 74/79] Skip a test observed to fail in koji on x86_64 --- uv.spec | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/uv.spec b/uv.spec index e45492a..5c58aae 100644 --- a/uv.spec +++ b/uv.spec @@ -723,6 +723,12 @@ skip="${skip-} --skip user_agent_version::test_user_agent_has_version" # } # There are probably more of these. skip="${skip-} --skip retry::tests::retried_status_codes" +# This has been seen to fail in koji, so far only on x86_64, but so far not in +# a local mock build. It’s very possible that this is another testing race +# condition that would be avoided by process isolation in “cargo nextest.” It +# seems unlikely that it is a real and serious problem, although a proper +# diagnosis would be welcome. +skip="${skip-} --skip interpreter::tests::test_cache_eviction_with_unchanged_executable" %cargo_test -- -- --exact ${skip-} %endif From 4f3c8ab906c8e44359c454382f7d2b9545df3ef3 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 3 Sep 2026 19:14:22 +0100 Subject: [PATCH 75/79] Update to 0.12.8 --- sources | 2 +- uv.spec | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/sources b/sources index bc35ac8..c2be955 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.12.7.tar.gz) = 7f9bd1aef6c285aedd3fe588a5f70e0458f85f6db14f0368ea24c5524fd66990510e0d5624a7faf48091a3dc73ff66ac52ab9a6ed571a10cca272b9588fb1aff +SHA512 (uv-0.12.8.tar.gz) = ecac878e03791c00875b7d1f0a1849ed165435e94d1ce999b4158be2bd305111ee69c418f4e75bb15541089a29a15a86e4201a56b024cdcf522554b925829e49 diff --git a/uv.spec b/uv.spec index 5c58aae..7f4b486 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.12.7 +Version: 0.12.8 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From 115172f53a772ecc15fec28d0a7f52f0c5861966 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Thu, 3 Sep 2026 20:38:09 +0100 Subject: [PATCH 76/79] Update to 0.12.9 (close RHBZ#2515847) --- sources | 2 +- uv.spec | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/sources b/sources index c2be955..4aad50d 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.12.8.tar.gz) = ecac878e03791c00875b7d1f0a1849ed165435e94d1ce999b4158be2bd305111ee69c418f4e75bb15541089a29a15a86e4201a56b024cdcf522554b925829e49 +SHA512 (uv-0.12.9.tar.gz) = 18d35675a3e15531a9542c951b265866da4b762e0f2ba91f66dcc8b55ba5352ec97638ee2dc7fd3a908639201b27a442112a75c67053f9d861840c041e0b5290 diff --git a/uv.spec b/uv.spec index 7f4b486..ce9028c 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.12.8 +Version: 0.12.9 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See From f0dec896926970119d4ae59cd30d2ffd291bce67 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Fri, 4 Sep 2026 17:33:42 +0100 Subject: [PATCH 77/79] =?UTF-8?q?Skip=20another=20test=20that=E2=80=99s=20?= =?UTF-8?q?flaky=20due=20test=20envvar=20races?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- uv.spec | 1 + 1 file changed, 1 insertion(+) diff --git a/uv.spec b/uv.spec index ce9028c..1e45eb1 100644 --- a/uv.spec +++ b/uv.spec @@ -723,6 +723,7 @@ skip="${skip-} --skip user_agent_version::test_user_agent_has_version" # } # There are probably more of these. skip="${skip-} --skip retry::tests::retried_status_codes" +skip="${skip-} --skip retry::tests::retry_logs_redact_signed_urls" # This has been seen to fail in koji, so far only on x86_64, but so far not in # a local mock build. It’s very possible that this is another testing race # condition that would be avoided by process isolation in “cargo nextest.” It From a043d4444fbe31a884ffc870e10189ba8799a855 Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Sat, 5 Sep 2026 07:47:09 +0100 Subject: [PATCH 78/79] Update to 0.12.0 (close RHBZ#2528984) --- 21434.patch | 78 ----------------------------------------------------- sources | 2 +- uv.spec | 5 +--- 3 files changed, 2 insertions(+), 83 deletions(-) delete mode 100644 21434.patch diff --git a/21434.patch b/21434.patch deleted file mode 100644 index 8a43884..0000000 --- a/21434.patch +++ /dev/null @@ -1,78 +0,0 @@ -From 9ded1ff23cb5d9c78c615ab0bb026942fac5d128 Mon Sep 17 00:00:00 2001 -From: Charlie Marsh -Date: Thu, 3 Sep 2026 07:24:08 -0400 -Subject: [PATCH] Remove Python invocation from dirhash tests - ---- - crates/uv-extract/src/dirhash.rs | 27 +++-------------------- - crates/uv-extract/test_vectors/dirhash.py | 5 +---- - 2 files changed, 4 insertions(+), 28 deletions(-) - -diff --git a/crates/uv-extract/src/dirhash.rs b/crates/uv-extract/src/dirhash.rs -index 76a0300ca51..943e13bd1fb 100644 ---- a/crates/uv-extract/src/dirhash.rs -+++ b/crates/uv-extract/src/dirhash.rs -@@ -519,7 +519,6 @@ mod tests { - - use super::*; - use std::cmp; -- use std::process::Command; - use std::task::{Context, Poll}; - - #[test] -@@ -806,10 +805,9 @@ mod tests { - - // `../test_vectors/test_vectors.json` contains a series of input trees and hashes, which is - // generated by `cargo dev generate-dirhash-test-vectors`. This tests both `dirhash_path` and -- // `DirhashTree` from this file, and also the `dirhash.py` Python implementation, so we're -- // testing that three different implementations agree. -- #[tokio::test] -- async fn test_vectors_json() -> anyhow::Result<()> { -+ // `DirhashTree` against the committed hashes. -+ #[test] -+ fn test_vectors_json() -> anyhow::Result<()> { - let test_vectors: Vec = - serde_json::from_str(include_str!("../test_vectors/test_vectors.json"))?; - for JsonTestVector { input, dirhash } in &test_vectors { -@@ -828,25 +826,6 @@ mod tests { - dirhash.as_str(), - dirhash_path(tempdir.path())?.to_hex().as_str(), - ); -- -- // Check the Python implementation, which also reads the FS. -- let python_script = Path::new(env!("CARGO_MANIFEST_DIR")) -- .join("test_vectors") -- .join("dirhash.py"); -- let output = Command::new("uv") -- .args(["run", "--locked", "--script"]) -- .arg(python_script) -- .arg(tempdir.path()) -- .output()?; -- assert!(output.status.success()); -- // This script's output is formatted like `md5sum` or `b3sum`, with each line including -- // a hash, a couple spaces, and a path. With only one path arg, there will be only one -- // line. -- let python_dirhash = std::str::from_utf8(&output.stdout)? -- .split_whitespace() -- .next() -- .unwrap(); -- assert_eq!(dirhash.as_str(), python_dirhash); - } - Ok(()) - } -diff --git a/crates/uv-extract/test_vectors/dirhash.py b/crates/uv-extract/test_vectors/dirhash.py -index fde1339670e..73ef480ca8a 100755 ---- a/crates/uv-extract/test_vectors/dirhash.py -+++ b/crates/uv-extract/test_vectors/dirhash.py -@@ -10,10 +10,7 @@ - # exclude-newer = "P7D" - # /// - --"""Independent Python implementation of ``uv_extract::dirhash``. -- --The Rust ``test_vectors_json`` test case exercises this implementation in CI. --""" -+"""Independent Python implementation of ``uv_extract::dirhash``.""" - - import sys - from pathlib import Path diff --git a/sources b/sources index 4aad50d..8c09ef2 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.12.9.tar.gz) = 18d35675a3e15531a9542c951b265866da4b762e0f2ba91f66dcc8b55ba5352ec97638ee2dc7fd3a908639201b27a442112a75c67053f9d861840c041e0b5290 +SHA512 (uv-0.12.10.tar.gz) = e9b4cb1bf5f7e65d666f1e4f9a957964508f0f7b531f682e75b9a64a58cf0fe0ead1b1639e0f8ed37df8cbf39cde42fa02d7df2e6cecec3615034907d85127a2 diff --git a/uv.spec b/uv.spec index 1e45eb1..ed51ebd 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.12.9 +Version: 0.12.10 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See @@ -160,9 +160,6 @@ Patch: uv-0.12.1-revert-blake2-beta.patch # Add license texts for new contents of test/ecosystem/ from PR#20068 # https://github.com/astral-sh/uv/pull/20174 Patch: %{url}/pull/20174.patch -# Remove Python invocation from dirhash tests -# https://github.com/astral-sh/uv/pull/21434 -Patch: %{url}/pull/21434.patch BuildSystem: pyproject BuildOption(install): --assert-license uv From 11b4c1bfae74eedfc3319376bd59b6b8cf938a0c Mon Sep 17 00:00:00 2001 From: "Benjamin A. Beasley" Date: Wed, 9 Sep 2026 18:24:08 +0100 Subject: [PATCH 79/79] Update to 0.12.12 (close RHBZ#2530499) --- sources | 2 +- uv.spec | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/sources b/sources index 8c09ef2..6579b89 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (uv-0.12.10.tar.gz) = e9b4cb1bf5f7e65d666f1e4f9a957964508f0f7b531f682e75b9a64a58cf0fe0ead1b1639e0f8ed37df8cbf39cde42fa02d7df2e6cecec3615034907d85127a2 +SHA512 (uv-0.12.12.tar.gz) = 9242adfa1f0508db02215766d62d6129043b8cfc6b488ba4d7a3889c334786f58717559625187f38ce9f53060f1a2063b8ea59a71d63c8c7a836bc73a99be6d5 diff --git a/uv.spec b/uv.spec index ed51ebd..6086cd1 100644 --- a/uv.spec +++ b/uv.spec @@ -5,7 +5,7 @@ %bcond other_python_versions %{undefined epel} Name: uv -Version: 0.12.10 +Version: 0.12.12 # The uv package has a permanent exception to the Updates Policy in Fedora, so # it can be updated in stable releases across SemVer boundaries (subject to # good judgement and actual compatibility of any reverse dependencies). See